SAP Security Note
Medium priority
SAP security note 1238862, “Security Enhancement for WFD”, is a program error note released on October 8, 2009. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This security note addresses vulnerabilities related to Cross-Site Request Forgery (XSRF) and Cross-Site Scripting (XSS) in the Workforce Deployment (WFD) application.
Solution
To mitigate these security risks, apply the following patches:
- SAP SHARED JAVA.APPLIC. 5.0 SP12 patch 09 or higher. The fix is included in Support Package 13 of SAP SHARED JAVA.APPLIC. 5.0 (Java component SAP-SHRAPP 5.00).
For obtaining the patch, refer to SAP Note 877887.
Affected components
- SAP-CRMJAV 5.0
- SAP-CRMWEB 5.0
- SAP-SHRWEB 5.0
- SAP-SHRJAV 5.0
- SAP-CRMAPP 5.0
- SAP-SHRAPP 5.0
Full note on SAP: SAP Support Launchpad note 1238862
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



