SAP Knowledge Base Article - Preview

3461209 - AppScan identified the password parameter received in the query string

Symptom

A security scanning tool has found a potential vulnerability in an XS Classic URL.

Issue Title
[high priority]Password parameters included in the query

Detailed Description
AppScan identified the password parameter received in the query string

Recommended Solution
Fix: Always use SSL and POST (body) parameters when sending sensitive information.


Read more...

Environment

SAP HANA Database 2.0.

Product

SAP HANA, platform edition 2.0

Keywords

KBA , HAN-DB-SEC , SAP HANA Security & User Management , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.