cancel
Showing results for 
Search instead for 
Did you mean: 

Fiori Security Concerns

09-02-2015 12:34 PM
986 views 4 comments Go to solution
0 Likes
SAP Managed Tags
Subscribe

Hi Experts,


We are implementing Fiori UX Solution in our customer SAP Landscape. We are done with proof of concept implementation and now we are heading towards the actual development in Dev environment.  Now we got some queries from security team that how we are going to address security related issues in Fiori development like Phishing, Injections, Man in Middle attacks, Snooping etc etc. I am sure that SAP might have taken all these points into consideration while delivering Enterprise Fiori solution as these apps deal with Secure customer data. Is there any readymade document or some info blogs available by SAP or someone else which addresses all these security concerns. And am looking for addressing security concerns in below two possible scenarios.


1. Without any customisations to the existing Fiori apps other than deployment in customer landscape. (Expecting SAP would have delivered a security guide as part of their UX release but don't have any link or docs with me currently)

2. With few client side UI customisations to the standard Fiori apps. (Obviously front end developer has to take care of this security like by avoiding local storage of secure information and strong in an encrypted storage if required etc etc)


Could you please share your thoughts or some links which I can use as reference for above mentioned query.


Thanks in advance.

Regards,

Arun.

0 Likes

Accepted Solutions (1)

Accepted Solutions (1)

HPSeitz
Active Participant
0 Likes

Hi Arun,

regarding No 2) "Custom SAPUI5 Development":

  • a good source for SAPUI5 Frontend Developer (as SAP Fiori is based on SAPUI5 for the frontend) is the very valuable video from Jens Himmelrath.

Some general thoughts about SAPUI5 security:

  • All web security issues are potential SAPUI5 issues
  • main problem is XSS (Cross Site Scripting)
  • Standard SAPUI5 is generally secured against attacks

SAPUI5 is client side only. To have secure application also the backend needs to be secured

Best Regards,

HP

Answers (2)

Answers (2)

Former Member
0 Likes

Hi All,

Am currently looking into Mocana Mobile Security Solution by SAP for all enterprise related mobile apps. It seems to be quite matching solution for my current requirement. It is kind of MDM solution. Currently we are using Airwatch MDM so am planning to check with concerned Airwatch team too to know whether they are providing any such kind of security solution for SAP Mobile apps. I will keep update this post once am done with my findings.

Regards,

Arun.

nageshcaparthy
Product and Topic Expert
Product and Topic Expert
0 Likes

Hi Arun,

On Question, you an refer to RDS Solution it covers the entire details on Basic Security and Advance Security.

RDS Overview: https://fioriapps-rds.dispatcher.hana.ondemand.com/docu/RDS_FIORI_NWG20V6_Solution_Detail_en_XX.pdf

You can download it from: SAP Service Marketplace - SAP Fiori Apps

Document Number: EE1 & EE2

You may also refer to :http://www.sdn.sap.com/irj/scn/go/portal/prtroot/docs/library/uuid/d066cce7-b7b8-3010-428c-bcef3cf76...

Hope this helps.

Regards,

Nagesh

Former Member
0 Likes

Thanks Nagesh. I will go through the document and will get back incase of any queries.