Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-site request forgery protection for stateless, SAP security note 1551982

SAP Note 1551982
SAP Security Note
High priority

SAP security note 1551982, “Cross-site request forgery protection for stateless”, is a program error note released on 02.03.2012. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBusiness Server Pages (BC-BSP)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version10
StatusReleased for Customer
Released on02.03.2012
LanguageEnglish

Description

Symptom

This security note has been updated. For more detailed information, see Security Note 1670352.

The correction within this note only provides a framework for the XSRF protection. To secure a specific application, configuration and sometimes adaptation effort are required. For applications delivered by SAP, check for corresponding notes that will set XSRF protection accordingly. If you would like to protect your own custom application, please follow the detailed instructions described in Note 1458171. Activation of protection for a stateless BSP and a stateful BSP is performed via the same configuration and adaptation steps.

Solution

The XSRF generic protection of BSP is based on the secure token method.

Important for System 620:

  • Ensure your system has at least Kernel 640 PL 325 according to Note 1410294.
  • Perform manual steps for SPs lower than SP71: in transaction SE16, enter RSECACHK for Table Name, press ‘Create Entries’ (F5), insert KRN/SNT/SNTXXHMAC for PROGNAME and 2B5E0AB3E6C75C4CDF7556BC8FF2DFBC for CHSUM, then save. Then in transaction SE16 again, enter RSECACHK for Table Name, press ‘Table Contents’ (F7), mark the entry KRN/SNT/SNTXXHMAC, go to ‘Table Entry’ > ‘Transport Entries’ in the menu, and insert the transport you opened for these changes.

Note: the prerequisites mentioned under SP Patch Level are only relevant for release 7.31.

Causing side effects: 1658516: Applets fail due to XSRF protection (COOKIE_NOT_FOUND).

References

Affected components

  • SAP_BASIS: 620 to 640
  • SAP_BASIS: 700 to 702
  • SAP_BASIS: 710 to 730
  • SAP_BASIS: 731 to 731

Full note on SAP: SAP Support Launchpad note 1551982

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More