Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security Check of Internet Sales, SAP security note 646140

SAP Note 646140

SAP security note 646140, "Security Check of Internet Sales". Below are the symptom and SAP recommended solution.

Description

Symptom

You want to secure your Internet Sales application.

Solution

This note provides information on how to secure the Internet Sales application. Follow the steps below to enhance the security of your system:

  • Protecting Internet Sales (ISA) Administration Pages:
    • Creating a New User for ISA Administration: Create a new user on the J2EE engine and allow only this user to access the ISA administration pages. See Note 502803
    • Changing Password of J2EE Engine Administrator: The Administrator user must not be used for accessing the ISA administration pages. Ensure the password of the Administrator is different from the password of the user accessing the ISA pages. See Note 603142
    • Restricting Access to ISA Administration Pages from the Internet: Limit access to the ISA administration pages to prevent unauthorized internet access. See Note 675049. If using Apache HTTP server, refer to Note 708138.
    • Turning Off Further Features of the Administration Pages: Disable additional features as described in Note 645923. In ISA 4.0 SP06 or higher, the following features are turned off: appinfo and logfiledownload.
  • Securing Files Containing Sensitive Data After Deployment: Secure files that contain sensitive data, such as logon data to the CRM system. See Note 675125
  • Logging/Tracing:
    • Turning Off Tracing in Productive Systems: Set the trace level to ERROR to minimize logging in productive environments. Refer to the CRM E-Selling: Business Scenario Configuration Guide for more details.
    • Handling RFC Tracing in ISA: Ensure that sensitive data is not traced when enabling RFC tracing for any function module. See Note 644288
  • Disabling ‘showstacktrace’ Feature in Productive Systems: Prevent disclosure of stack traces by turning off the showstacktrace feature. See Note 702408
  • Applying Security Relevant Patches:
    • B2C:
      • 624393 – Sales order of other users can be displayed authentication
      • 625135 – CRM ABAP solution: Display orders of other users
      • 625402 – ‘Remote-enabled’ flag for CRM_ISA_BASKET_GETPAYMENT
      • 627649 – Credit card data is stored in the log file
      • 725954 – Features having impact on Security are disabled in LWC
    • B2B R/3 Edition:
      • 827869 – Logging of JCO Password in R3CatalogServerEngine
  • Restricting Access to Shop Administration Application in R/3 Scenario: See Note 693832
  • SAP J2EE Engine 6.20:

References

Full note on SAP: SAP Support Launchpad note 646140

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More