CSRF Protection Failure
search cancel

CSRF Protection Failure

book

Article ID: 276146

calendar_today

Updated On:

Products

Information Centric Analytics

Issue/Introduction

In the Information Centric Analytics (ICA) console, when clicking the Open Original Message link at the bottom of a View DIM Payload window for an incident from Symantec DLP, a CSRF Protection Failure error message is displayed in a new browser window or tab:

The requested page failed CSRF protection check. Please click the link below to return to Enforce.

Environment

Version : ICA 6.x
               
DLP 16.0.x

Component : Symantec DLP Integration Pack

Cause

With DLP 16.0 MP1 (16.0.001), DLP added Cross-Site Request Forgery (CSRF) protection for certain Enforce URLs. This broke ICA’s deep linking into DLP to download original messages for network incidents.

Resolution

To workaround this issue, use the View in DLP button rather than the View DIM Payload button in the ICA console.

A hotfix has been released to address this issue. ICA 6.6 MP1 HF2 is available for download from the Broadcom support portal.