SAP Knowledge Base Article - Preview

3161405 - Signavio-id should be removed from URL

Symptom

Passing sensitive information in URL is against recommended security best practices. Sensitive information within URLs may be logged in various locations, including the user's browser, the web server, and any forward or reverse proxy servers between the two endpoints. URLs may also be displayed on-screen, bookmarked or emailed around by users. They may be disclosed to third parties via the Referrer header when any off-site links are followed. Placing session tokens into the URL increases the risk that they will be captured by an attacker.



Read more...

Product

SAP Process Collaboration Hub by Signavio all versions

Keywords

KBA , BPI-SIG-HUB , SAP Signavio Process Collaboration Hub , Product Enhancement

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.