Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

Update #1 to security note 1522651, SAP security note 1536087

Description

After you apply the note 1522651 and you click on some links within SRM you receive errors stating

  • “ITS_P:019 XSRF no sec_sesstoken”
  • “Conflict when starting service … Service call … to transaction was terminated because ok code … is prohibited as start ok code in service … for transaction”

Available fix and Supported packages

  • SRM_SERVER | 500 | 500
  • SRM_SERVER | 550 | 550
  • SRM_SERVER 500 | SAPKIBKS17 |
  • SRM_SERVER 550 | SAPKIBKT18 |

Affected component

    SRM-EBP-TEC-ITS
    ITS and Web files

CVSS

Score: 0

Exploit

Exploit is not available.
For detailed information please contact the mail [email protected].

URL

https://launchpad.support.sap.com/#/notes/1536087

TAGS

#409
#CONFLICT
#ITS_P
#019
#~sec_sesstoken
#sec_sesstoken

More to explorer