SAP Security Note
High priority
SAP security note 1571684, "Protect against cross-site request forgery for ITSmobile Services", is a program error note released on 13.12.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
A cross-site request forgery (CSRF) is an attack on web applications. For detailed information about this attack, see the Wikipedia article on the subject.
This SAP Note describes a generic protection mechanism that should protect the ITSmobile services from attacks of this kind. You must configure each of your user-defined ITS services as described below to activate the XSRF protection for user-defined ITS services that are not among the ITS services delivered by SAP.
For more information about XSRF protection in ITS services in general, see Note 1481392 "Cross Site Request Forgery Protection for ITS".
Solution
- Import the relevant Basis Support Packages.
- Use transaction SICF to set the GUI parameter ~XSRFCHECK to "1" (without quotation marks) in your ITSmobile services.
References
This note refers to
- Note 1892083 – Further coverage for SAP Note 1571684
- Note 1708362 – SAP GUI for HTML: Correction instructions for SAP Note 1571684
- Note 1597489 – Unauthorized use of application functions in SCM-EWM-RF
- Note 1481392 – Cross Site Request Forgery Protection for ITS
- Note 1521808 – ITS: Follow-up tasks for XSRF framework
- Note 1552922 – SAP GUI for HTML: Minor corrections in the spring of 2011
Full note on SAP: SAP Support Launchpad note 1571684
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
