<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Exploits (Java Script, Flash, ActiveX) - SAP principles found where? in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/exploits-java-script-flash-activex-sap-principles-found-where/m-p/6411454#M1407951</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi people!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAP releases support for rich Web Browser applications in Web Dynpro (Flash).&lt;/P&gt;&lt;P&gt;The use of the Web Browser as FrontEnd in Business transactions will grow in the future.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Every week we read of new exploits in applications that enriches the Web Browsers.&lt;/P&gt;&lt;P&gt;It could be Java Script, Flash or ActiveX. Like this for example:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.computerworld.com/s/article/9140768/Flash_flaw_puts_most_sites_users_at_risk_say_researchers" target="test_blank"&gt;http://www.computerworld.com/s/article/9140768/Flash_flaw_puts_most_sites_users_at_risk_say_researchers&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some exploits has over the years been so severe that users have been recommended to deactivate the application until a solution is delivered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we are dependent of the Web Browser application for important Business Transactions it becomes more problematic to deactivate it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I am looking for information around this area.&lt;/STRONG&gt; I have not found anything in SAPNet or SDN, but I have some problems knowing where to look. I have not found this aspect somewhere. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have information of official documents or URLs, please provide it in this thread.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Lasse&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Nov 2009 10:50:56 GMT</pubDate>
    <dc:creator>Former Member</dc:creator>
    <dc:date>2009-11-18T10:50:56Z</dc:date>
    <item>
      <title>Exploits (Java Script, Flash, ActiveX) - SAP principles found where?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/exploits-java-script-flash-activex-sap-principles-found-where/m-p/6411454#M1407951</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi people!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SAP releases support for rich Web Browser applications in Web Dynpro (Flash).&lt;/P&gt;&lt;P&gt;The use of the Web Browser as FrontEnd in Business transactions will grow in the future.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Every week we read of new exploits in applications that enriches the Web Browsers.&lt;/P&gt;&lt;P&gt;It could be Java Script, Flash or ActiveX. Like this for example:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.computerworld.com/s/article/9140768/Flash_flaw_puts_most_sites_users_at_risk_say_researchers" target="test_blank"&gt;http://www.computerworld.com/s/article/9140768/Flash_flaw_puts_most_sites_users_at_risk_say_researchers&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some exploits has over the years been so severe that users have been recommended to deactivate the application until a solution is delivered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If we are dependent of the Web Browser application for important Business Transactions it becomes more problematic to deactivate it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;I am looking for information around this area.&lt;/STRONG&gt; I have not found anything in SAPNet or SDN, but I have some problems knowing where to look. I have not found this aspect somewhere. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have information of official documents or URLs, please provide it in this thread.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;Lasse&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Nov 2009 10:50:56 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/exploits-java-script-flash-activex-sap-principles-found-where/m-p/6411454#M1407951</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2009-11-18T10:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: Exploits (Java Script, Flash, ActiveX) - SAP principles found where?</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/exploits-java-script-flash-activex-sap-principles-found-where/m-p/6411455#M1407952</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not 100% sure if this will help, but you could have a look at two places:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SAP Security Guides&lt;/STRONG&gt;: [https://websmp210.sap-ag.de/securityguide]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  There are security guides for all applications / installations giving recommendations on how to secure the systems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SAP Security notes&lt;/STRONG&gt;: [https://websmp102.sap-ag.de/securitynotes]&lt;/P&gt;&lt;P&gt;These SAP OSS notes describe security issues in various SAP components including web applications. On monthly basis security issues and their solutions are published here&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Maaike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Dec 2011 10:26:45 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/exploits-java-script-flash-activex-sap-principles-found-where/m-p/6411455#M1407952</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2011-12-28T10:26:45Z</dc:date>
    </item>
  </channel>
</rss>

