<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Web GUI security precautions in Application Development and Automation Discussions</title>
    <link>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637409#M1942829</link>
    <description>&lt;P&gt;Dear Tamas,&lt;/P&gt;&lt;P&gt;I hope you are doing good! Though, this question seems to be old, but I have a similar request: I was told that SAP Security team is recommending to keep the ITS-WEBGUI node deactivated. But for Screen Personas to work, according to this &lt;A href="https://help.sap.com/viewer/9db44532734f4718b91e460c020307fe/Current/en-US/4a8b1bf790a545fa939b8183bdac0ca8.html"&gt;link&lt;/A&gt;, it has to be active. Is this a known issue and already resolved with one of the mentioned notes? &lt;/P&gt;&lt;P&gt;Thank you for the support and a big hello to the rest of the team! &lt;/P&gt;&lt;P&gt;BR Aleks&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jun 2022 06:33:04 GMT</pubDate>
    <dc:creator>former_member596519</dc:creator>
    <dc:date>2022-06-30T06:33:04Z</dc:date>
    <item>
      <title>Web GUI security precautions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637400#M1942820</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;Hi SAP personas team, Security topic:Since Web GUI works on browser and we use Scripting (Via BAPI's) What are the security precautions one should consider? When i did some research i found this link &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://erpscan.com/wp-content/uploads/presentations/2012-Kuwait-InfoSecurity-Top-10-most-interesting-vulnerabilities-and-attacks-in-SAP.pdf"&gt;https://erpscan.com/wp-content/uploads/presentations/2012-Kuwait-InfoSecurity-Top-10-most-interesting-vulnerabilities-and-attacks-in-SAP.pdf&lt;/A&gt;&lt;SPAN&gt; What steps did SAP take to avoid vulnerable attacks via Internet. Could you please send us the important notes that we can look in to&amp;nbsp; if any Kindly suggest. Best regards, pradeep.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 May 2016 10:24:41 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637400#M1942820</guid>
      <dc:creator>pakula123</dc:creator>
      <dc:date>2016-05-17T10:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: Web GUI security precautions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637401#M1942821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Pradeep,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You probably read about the &lt;A href="https://launchpad.support.sap.com/#/securitynotes"&gt;SAP Security Notes&lt;/A&gt;. Please go ahead and check the notes published at the SAP One Support Portal. You will need assistance from your Security team to assess whether a note is required in your system or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, the SAP Security Notes will be updated as soon as a particular vulnerability is found and fixed. This is the resource you need to use to prevent risks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Cris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 May 2016 11:05:39 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637401#M1942821</guid>
      <dc:creator>cris_hansen</dc:creator>
      <dc:date>2016-05-17T11:05:39Z</dc:date>
    </item>
    <item>
      <title>Re: Web GUI security precautions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637402#M1942822</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Cristiano .Your&amp;nbsp; reply was at the speed of HANA . Best regards, pradeep.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 May 2016 11:13:52 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637402#M1942822</guid>
      <dc:creator>pakula123</dc:creator>
      <dc:date>2016-05-17T11:13:52Z</dc:date>
    </item>
    <item>
      <title>Re: Web GUI security precautions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637403#M1942823</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Pradeep.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am here to help. Not always as fast as HANA. &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro_emoticon jive_macro jive_emote" src="https://community.sap.com/108/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;All the best,&lt;/P&gt;&lt;P&gt;Cris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 May 2016 11:30:46 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637403#M1942823</guid>
      <dc:creator>cris_hansen</dc:creator>
      <dc:date>2016-05-17T11:30:46Z</dc:date>
    </item>
    <item>
      <title>Re: Web GUI security precautions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637404#M1942824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Cristiano , I tried to open the link that you have sent.It took us to general place where we check the notes , Can you be more specific about the note numbers that we need to implement for Personas ? Best regards, pradeep.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 May 2016 20:48:50 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637404#M1942824</guid>
      <dc:creator>pakula123</dc:creator>
      <dc:date>2016-05-17T20:48:50Z</dc:date>
    </item>
    <item>
      <title>Re: Web GUI security precautions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637405#M1942825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Pradeep,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to check the list from time to time, looking for BC-FES-ITS, BC-FES-WGU and BC-PER notes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;Cris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 May 2016 16:51:13 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637405#M1942825</guid>
      <dc:creator>cris_hansen</dc:creator>
      <dc:date>2016-05-18T16:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: Web GUI security precautions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637406#M1942826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you have SP03 installed, the new Notes Checker feature makes it easy to verify whether the required notes are implemented. If there are any new notes identified as required regarding security and relevant for Personas, this tool will recognize that and tell you if anything is missing.&lt;/P&gt;&lt;P&gt;However this relies on the Personas team getting notified about such notes so that we can make sure the Notes Checker knows about them. We try our best to keep up with this of course but in some cases it is possible that a note only applies to certain situations therefore it cannot be made required for all customers. In such cases, the local basis team has to determine whether the note should be implemented.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 May 2016 17:10:19 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637406#M1942826</guid>
      <dc:creator>Tamas_Hoznek</dc:creator>
      <dc:date>2016-05-18T17:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: Web GUI security precautions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637407#M1942827</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why not use Solution Manager to pull the available SAP Notes for any given system?&amp;nbsp; See attached Screen Shot.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dan Mead&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 May 2016 18:08:55 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637407#M1942827</guid>
      <dc:creator>Former Member</dc:creator>
      <dc:date>2016-05-18T18:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Web GUI security precautions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637408#M1942828</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for you note Daniel.&amp;nbsp; I forwarded this info to concerned team. Best regards, pradeep.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 May 2016 00:23:55 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637408#M1942828</guid>
      <dc:creator>pakula123</dc:creator>
      <dc:date>2016-05-19T00:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: Web GUI security precautions</title>
      <link>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637409#M1942829</link>
      <description>&lt;P&gt;Dear Tamas,&lt;/P&gt;&lt;P&gt;I hope you are doing good! Though, this question seems to be old, but I have a similar request: I was told that SAP Security team is recommending to keep the ITS-WEBGUI node deactivated. But for Screen Personas to work, according to this &lt;A href="https://help.sap.com/viewer/9db44532734f4718b91e460c020307fe/Current/en-US/4a8b1bf790a545fa939b8183bdac0ca8.html"&gt;link&lt;/A&gt;, it has to be active. Is this a known issue and already resolved with one of the mentioned notes? &lt;/P&gt;&lt;P&gt;Thank you for the support and a big hello to the rest of the team! &lt;/P&gt;&lt;P&gt;BR Aleks&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 06:33:04 GMT</pubDate>
      <guid>https://community.sap.com/t5/application-development-and-automation-discussions/web-gui-security-precautions/m-p/11637409#M1942829</guid>
      <dc:creator>former_member596519</dc:creator>
      <dc:date>2022-06-30T06:33:04Z</dc:date>
    </item>
  </channel>
</rss>

