Symptom
- User can upload executable files disguised as office files or double extension files.
- For example, a ".exe" file can be uploaded by modifying the extension from ".exe" to ".exe.pdf" (In this case upload is successfully done because ".pdf" is an allowed mime type.
Read more...
Environment
- SAP S/4HANA
Product
SAP S/4HANA 2020
Keywords
Allowed MIME types BOPF attachment reusable Transportation Manager attachments TM EWM VSCANPROFILE Executable file .exe, KBA , CA-EPT-BRC-ATF , Dependent Object for Attachment Folder , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview