SAP security note 1536087, "Update #1 to security note 1522651", is a program error note released on 14.12.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
After applying note 1522651, clicking on some links within SRM results in the following errors: "ITS_P:019 XSRF no sec_sesstoken" and "Conflict when starting service … Service call … to transaction was terminated because ok code … is prohibited as start ok code in service … for transaction".
Solution
- Refer to Note 1481392 for additional information; its corrections are a prerequisite for this update.
- Implement the correction instructions of this note, which create the report ITS_XSRF_PARAM_SRM_2 in your system.
- Execute the report ITS_XSRF_PARAM_SRM_2 (only after running ITS_XSRF_PARAM_SRM from Note 1522651), specifying a transport request number when prompted; the report adds service parameters for the adapted ITS services, maintainable via the GUI configuration pushbutton for a service in transaction SICF.
- Then apply the SRM correction either via the corresponding Support Package, or via SNOTE code changes (which may only work correctly with SRM_SERVER 500/550 SP 15 or higher; lower SP releases might also work).
Reason and prerequisites
Program error.
References
- 1522651: XSRF activation in ITS Services
- 1518849: SRM 5.0 SP stack 18(02/2011) SAPKIBKT18 release/info note
Affected components
- SRM_SERVER 500
- SRM_SERVER 550
Full note on SAP: SAP Support Launchpad note 1536087
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
