SAP Security Note
Medium priority
SAP security note 1501919, "Start.jsp enhancements", is a special development note released on 13.05.2011. Below are the symptom and SAP recommended solution.
Description
Symptom
This security note has been updated. For details, see security note 1587785.
You are using the Start.jsp for your CRM Web Channel application. In addition, you have activated the security settings SecuritySessionIDHTTPSProtection or SystemCookiesHTTPSProtection of your Web application server Java. However, problems occur when you call Extended Configuration Management links on the Start.jsp page.
Solution
This note contains Java corrections for E-Commerce and CRM Web Channel.
- Software component: SAP-SHRWEB
- Development components: crm/tc/web/xcmadmin
- Changed files: start.jsp
Apply the Support Package patch level specified in this note.
Reason and prerequisites
There is a program error.
References
Full note on SAP: SAP Support Launchpad note 1501919
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



