Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Security Enhancement for WFD, SAP security note 1238862

SAP Note 1238862
SAP Security Note
Medium priority

SAP security note 1238862, “Security Enhancement for WFD”, is a program error note released on October 8, 2009. Below are the symptom, SAP recommended solution and the affected software components.

ComponentCustomer Relationship Management > Workforce Deployment > Multi-Site Workforce Deployment (CRM-WFD-RTL)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Released onOctober 8, 2009

Description

Symptom

This security note addresses vulnerabilities related to Cross-Site Request Forgery (XSRF) and Cross-Site Scripting (XSS) in the Workforce Deployment (WFD) application.

Solution

To mitigate these security risks, apply the following patches:

  • SAP SHARED JAVA.APPLIC. 5.0 SP12 patch 09 or higher. The fix is included in Support Package 13 of SAP SHARED JAVA.APPLIC. 5.0 (Java component SAP-SHRAPP 5.00).

For obtaining the patch, refer to SAP Note 877887.

Affected components

  • SAP-CRMJAV 5.0
  • SAP-CRMWEB 5.0
  • SAP-SHRWEB 5.0
  • SAP-SHRJAV 5.0
  • SAP-CRMAPP 5.0
  • SAP-SHRAPP 5.0

Full note on SAP: SAP Support Launchpad note 1238862

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More