SAP security note 1536193, "Update #2 to security note 1522651", is released on 14.12.2010. Below are the symptom and SAP recommended solution.
Description
Symptom
After applying note 1522651, clicking on some links within SRM results in the following errors: "ITS_P:019 XSRF no sec_sesstoken" and "Conflict when starting service … Service call … to transaction was terminated because ok code … is prohibited as start ok code in service … for transaction".
Solution
- Refer to Note 1481392 for additional information and instructions; its corrections are a prerequisite for implementing this note.
- Then either apply the SRM correction via the corresponding Support Package, or apply the SRM code changes via SNOTE (this may only work properly with at least SRM_SERVER 500/550 SP 15; lower SP releases might work).
Reason and prerequisites
Program error.
References
- 1522651 – XSRF activation in ITS Services
- 1518849 – SRM 5.0 SP stack 18(02/2011) SAPKIBKT18 release/info note
Full note on SAP: SAP Support Launchpad note 1536193
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



