SAP Note 1509014 - Unauthorized usage of application functionality in PA-ER

Composant : E-Recruiting -

Solution : https://service.sap.com/sap/support/notes/1509014 (Connexion à SAP Service Marketplace requise)

Mots Clés :
terms cross-site request forgery, cross site scripting attack, prerequisites pa-er executes, pa-er reason, transport request number, bsp applications adapted, referencing specific urls, database table bsptempxsrfstore, specific parameters, table entries

Notes associées :

1540729ASU content for activating XSRF protection for BSP
1520324Advance creation of XSRF information
1458171Cross Site Request Forgery Protection for BSP