SAP security note 1521197, "Update #1 to Security Note 1517094 Released". Below are the symptom and SAP recommended solution.
Description
Symptom
SAP Security Note 1521197 addresses critical issues encountered in CRM 4.0 IS after implementing and activating security-relevant changes in SAP NetWeaver (Note 1532777). Specifically, the CRM Interaction becomes non-startable from the browser, leading to multiple communication problems such as:
- CTI → Worker session
- Agent session → Worker session
- Browser (polling, SAM communication) → ICM or Worker Session
Common errors include: 400 Session not found, HTTPIO_USER_VALIDATION_SSOCOOKIE_MISSING (see Note 1266780), HTTPIO_USER_VALIDATION_SSOCOOKIE_INVALID.
Solution
Implementing this security note involves both automated corrections and manual activities.
After implementing both pre and post-installation steps, release and import the transports into the quality environment. Thoroughly test the CRM_IC application before moving changes to the production environment. Ensure that SICF entries are active in all systems across the landscape.
References
- Note 1532777 – Collective Note: ABAP Session Protection Recommendations
- Note 1517094 – CRM-IC: Session Access Token
- Note 1420203 – Enable foreign access to a stateful HTTP session
- Note 1310561 – SAP J2EE Engine Session Fixation Protection
- Note 1301591 – HTTP 400 – Session not found (Stateful HTTP communication)
- Note 1266780 – User check for each HTTP request
Full note on SAP: SAP Support Launchpad note 1521197
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



