SAP Security Note
High priority
SAP security note 1551982, “Cross-site request forgery protection for stateless”, is a program error note released on 02.03.2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This security note has been updated. For more detailed information, see Security Note 1670352.
The correction within this note only provides a framework for the XSRF protection. To secure a specific application, configuration and sometimes adaptation effort are required. For applications delivered by SAP, check for corresponding notes that will set XSRF protection accordingly. If you would like to protect your own custom application, please follow the detailed instructions described in Note 1458171. Activation of protection for a stateless BSP and a stateful BSP is performed via the same configuration and adaptation steps.
Solution
The XSRF generic protection of BSP is based on the secure token method.
Important for System 620:
- Ensure your system has at least Kernel 640 PL 325 according to Note 1410294.
- Perform manual steps for SPs lower than SP71: in transaction SE16, enter RSECACHK for Table Name, press ‘Create Entries’ (F5), insert KRN/SNT/SNTXXHMAC for PROGNAME and 2B5E0AB3E6C75C4CDF7556BC8FF2DFBC for CHSUM, then save. Then in transaction SE16 again, enter RSECACHK for Table Name, press ‘Table Contents’ (F7), mark the entry KRN/SNT/SNTXXHMAC, go to ‘Table Entry’ > ‘Transport Entries’ in the menu, and insert the transport you opened for these changes.
Note: the prerequisites mentioned under SP Patch Level are only relevant for release 7.31.
Causing side effects: 1658516: Applets fail due to XSRF protection (COOKIE_NOT_FOUND).
References
- 1666244: cFolders: Composite SAP Note – Security
- 1658828: Call of ROS questionnaire fails with “message type unknown”
- 1658516: Applets fail due to XSRF protection (COOKIE_NOT_FOUND)
- 1647006: Survey: “CALLED_BY_PUBLIC_SERVICE” in BSP application
- 1624909: Unauthorized use of application functions in BW-BCT-CRM-RTOM
- 1618640: Unauthorized use of application functions in CRM-ISE-WBF
- 1590175: Unauthorized use of application functions in CRM-MKT-DAM
- 1587581: Unauthorized use of application functions in workflow (BSP)
- 1560585: SAP Gateway 2.0 Release Note
Affected components
- SAP_BASIS: 620 to 640
- SAP_BASIS: 700 to 702
- SAP_BASIS: 710 to 730
- SAP_BASIS: 731 to 731
Full note on SAP: SAP Support Launchpad note 1551982
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




