SAP Security Note
High priority
SAP security note 1520324, "Advance Creation of XSRF Information", is an advance development note released on 30.01.2013. Below are the symptom and SAP recommended solution.
Description
Symptom
This security note has been updated. For details, see security notes 1566128, 1645355, and 1650039.
To protect applications from cross-site request forgery (XSRF) attacks, XSRF protection must be activated for each application. Implement the corrections described in this note to ensure this is possible in customer systems where a transport with XSRF protection development was implemented instead of importing the required Support Package.
Solution
This note establishes prerequisites for reports that create XSRF entries.
Important: Before implementing this note, ensure that the changes in Note 1458171 or Note 1532403 have already been implemented in your system.
References
- Unauthorized execution of application funcs. in BW-PLA-BPS-WIB
- cFolders: Composite SAP Note – Security
- Update #3 to Security Note 1520324
- Update #2 to Security Note 1520324
- Unauthorized use of application functions in WS-Browser
Full note on SAP: SAP Support Launchpad note 1520324
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
