Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Protectn against cross-site rqst forgery for ITSmobile Servs, SAP security note 1571684

SAP Note 1571684
SAP Security Note
High priority

SAP security note 1571684, "Protect against cross-site request forgery for ITSmobile Services", is a program error note released on 13.12.2011. Below are the symptom and SAP recommended solution.

CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on13.12.2011

Description

Symptom

A cross-site request forgery (CSRF) is an attack on web applications. For detailed information about this attack, see the Wikipedia article on the subject.

This SAP Note describes a generic protection mechanism that should protect the ITSmobile services from attacks of this kind. You must configure each of your user-defined ITS services as described below to activate the XSRF protection for user-defined ITS services that are not among the ITS services delivered by SAP.

For more information about XSRF protection in ITS services in general, see Note 1481392 "Cross Site Request Forgery Protection for ITS".

Solution

  • Import the relevant Basis Support Packages.
  • Use transaction SICF to set the GUI parameter ~XSRFCHECK to "1" (without quotation marks) in your ITSmobile services.

References

Full note on SAP: SAP Support Launchpad note 1571684

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More