Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CRM-IC Session Access Token, SAP security note 1517094

SAP Note 1517094
SAP Security Note
Medium priority

SAP security note 1517094, "CRM-IC: Session Access Token", is a program error note released on July 12, 2011. Below are the symptom and SAP recommended solution.

ComponentCA-GTF-IC-FRW-MES (Cross-Application Components)
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
StatusReleased for Customer
Released onJuly 12, 2011

Description

Symptom

After implementing and activating security-relevant changes in SAP Netweaver (Note 1532777), the CRM Interaction cannot be started from the browser due to several communication issues, such as: CTI → Worker session, Agent session → Worker session, Browser polling / SAM communication → ICM or Worker Session.

Errors observed include: "400 Session not found", HTTPIO_USER_VALIDATION_SSOCOOKIE_MISSING (Note 1266780), HTTPIO_USER_VALIDATION_SSOCOOKIE_INVALID.

Solution

  • Prerequisite: apply the correction from Note 1420203 (SAP_BASIS) to support Session Access Tokens.
  • Implement the corrections attached to this note based on your system’s Support Package and CRMUIF, WEBCUIF, or SAP_ABA version. Important: if applying CRMUIF corrections, do not apply the SAP_ABA correction.

References

Full note on SAP: SAP Support Launchpad note 1517094

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More