Symptom
A security concern is raised regarding scripted OData requests from SAP Fiori.
An authorized user can create a script that sends large amount of requests directly to an OData service by using the service name, session cookie, and CSRF token. The scripted requests can be repeated in a loop and may include modifying operations, such as POST, PUT, and DELETE.
Clarification is required on available SAP Gateway options to restrict or validate such requests.
Read more...
Environment
- SAP S/4HANA
- SAP NetWeaver
- SAP Gateway
Product
Keywords
SAP Gateway, OData, SAP Fiori, scripted requests, mass change, POST, PUT, DELETE, batch, $batch, CSRF token, session cookie, /IWFND/BD_MGW_RUNTIME, /IWFND/ES_MGW_RUNTIME, /IWFND/BD_MGW_DEST_FINDER, /IWFND/ES_MGW_DEST_FINDER , KBA , OPU-GW-COR , Framework , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview