Symptom
- User can upload executable files disguised as office files or double extension files.
- For example, a ".exe" file can be uploaded by modifying the extension from ".exe" to ".exe.pdf" (In this case upload is successfully done because ".pdf" is an allowed mime type.
Read more...
Environment
- SAP S/4HANA
Product
SAP S/4HANA 2020
Keywords
Allowed MIME types BOPF attachment reusable Transportation Manager attachments TM EWM VSCANPROFILE Executable file .exe, KBA , CA-EPT-BRC-ATF , Dependent Object for Attachment Folder , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.