SAP Knowledge Base Article - Preview

3772736 - Options to implement additional checks for scripted OData requests from SAP Fiori

Symptom

A security concern is raised regarding scripted OData requests from SAP Fiori.

An authorized user can create a script that sends large amount of requests directly to an OData service by using the service name, session cookie, and CSRF token. The scripted requests can be repeated in a loop and may include modifying operations, such as POST, PUT, and DELETE.

Clarification is required on available SAP Gateway options to restrict or validate such requests.


Read more...

Environment

  • SAP S/4HANA
  • SAP NetWeaver
  • SAP Gateway

Product

SAP Gateway all versions ; SAP NetWeaver all versions ; SAP S/4HANA foundation all versions

Keywords

SAP Gateway, OData, SAP Fiori, scripted requests, mass change, POST, PUT, DELETE, batch, $batch, CSRF token, session cookie, /IWFND/BD_MGW_RUNTIME, /IWFND/ES_MGW_RUNTIME, /IWFND/BD_MGW_DEST_FINDER, /IWFND/ES_MGW_DEST_FINDER , KBA , OPU-GW-COR , Framework , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.