Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Advance creation of XSRF information, SAP security note 1520324

SAP Note 1520324
SAP Security Note
High priority

SAP security note 1520324, "Advance Creation of XSRF Information", is an advance development note released on 30.01.2013. Below are the symptom and SAP recommended solution.

ComponentBC-BSP (Basis Components > Business Server Pages)
CategoryAdvance Development
PriorityCorrection with high priority
TypeSAP Security Note
Version16
StatusReleased for Customer
Released on30.01.2013
LanguageEnglish (Master Language: German)

Description

Symptom

This security note has been updated. For details, see security notes 1566128, 1645355, and 1650039.

To protect applications from cross-site request forgery (XSRF) attacks, XSRF protection must be activated for each application. Implement the corrections described in this note to ensure this is possible in customer systems where a transport with XSRF protection development was implemented instead of importing the required Support Package.

Solution

This note establishes prerequisites for reports that create XSRF entries.

Important: Before implementing this note, ensure that the changes in Note 1458171 or Note 1532403 have already been implemented in your system.

References

Full note on SAP: SAP Support Launchpad note 1520324

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More