SAP Security Note
High priority
SAP security note 1506858, “Security updates for Live Auction Cockpit”, is a program error note released on 14.12.2010. Below are the symptom, the SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 1506858 addresses critical security updates for the Live Auction Cockpit within the Supplier Relationship Management (SRM) component of SAP. This note resolves a Cross Site Request Forgery (XSRF) vulnerability and issues related to the re-login requirement when HTTPOnly cookie settings are enabled.
Solution
To mitigate the identified vulnerabilities, follow these steps:
- Apply Correction Instructions: Access the Correction Instructions and follow the provided guidelines to implement the necessary fixes.
- Update Live Auction Web Presentation Server (LACWPS): If you’re using LACWPS on JAVA, download and install the latest patch from the SAP Service Marketplace corresponding to your LACWPS release version.
References
- Note 1658516: Applets fail due to XSRF protection (COOKIE_NOT_FOUND)
- Note 1532777: Collective Note: ABAP Session Protection Recommendations
- Note 1420203: Enable foreign access to a stateful HTTP session
- Note 943336: HttpOnly cookie attribute
Affected components
- SRM_SERVER 500
- SRM_SERVER 550
- SRM_SERVER 600
- SRM_SERVER 700
- SRM_SERVER 701
Full note on SAP: SAP Support Launchpad note 1506858
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




