SAP Note 1506855 - Unauthorized usage of functionality in workflow area

Component : WebFlow Notifications - Web Integration

Solution : https://service.sap.com/sap/support/notes/1506855 (SAP Service marketplace login required)

Key words :
terms cross site request forgery, cross site scripting attack, business workflow area, database table bsptempxsrfstore, referencing specific urls, bsp applications execute, correction instructions contained, transport request, bsp applications, specific parameters

Related Notes :

1520324Advance creation of XSRF information