Exploits (Java Script, Flash, ActiveX) - SAP principles found where?

Hi people!
SAP releases support for rich Web Browser applications in Web Dynpro (Flash).
The use of the Web Browser as FrontEnd in Business transactions will grow in the future.
Every week we read of new exploits in applications that enriches the Web Browsers.
It could be Java Script, Flash or ActiveX. Like this for example:
http://www.computerworld.com/s/article/9140768/Flash_flaw_puts_most_sites_users_at_risk_say_researchers
Some exploits has over the years been so severe that users have been recommended to deactivate the application until a solution is delivered.
If we are dependent of the Web Browser application for important Business Transactions it becomes more problematic to deactivate it.
I am looking for information around this area. I have not found anything in SAPNet or SDN, but I have some problems knowing where to look. I have not found this aspect somewhere.
If you have information of official documents or URLs, please provide it in this thread.
Cheers,
Lasse

Hi,
I'm not 100% sure if this will help, but you could have a look at two places:
SAP Security Guides: [https://websmp210.sap-ag.de/securityguide]
  There are security guides for all applications / installations giving recommendations on how to secure the systems.
SAP Security notes: [https://websmp102.sap-ag.de/securitynotes]
These SAP OSS notes describe security issues in various SAP components including web applications. On monthly basis security issues and their solutions are published here
Kind regards
Maaike

Similar Messages

  • How to Include JAVA script code in SAP BI7 web Reporting?

    How to Include JAVA script code in SAP BI7 web Reporting?

    In nw2004s there is a new web item called "Script" web item which lets you add javascript code. When you add javascript code in this web item, you don't need the opening and closing <script> tags...
    Hope it Helps
    Chetan
    @CP..

  • Java Script Woes

    Hello,
    I created a Web site from a prebuilt template, but I cannot get the navigation buttons to work. I coded it correctly in Flash, but there is something wrong with the Java script, and I don't know where to look to see the problem.
    Is there someone on this forum who is willing to take a look at the Java script file to see what is wrong? The Web hosting company who supplied the template says they don't offer Flash support.
    Please let me know.
    Thanks,
    Kay

    JavaScript (LiveScript, ECMAScript) is indeed not the same as Java.
    You're in the wrong place for JavaScript questions. You better post JavaScript related questions at JavaScript related forums. There are ones at [http://webdeveloper.com] and [http://dynamicdrive.com].

  • Java Script alert

    Hello anyone out there. I am running OS 10 all updated. I am
    trying to install the trial version of dreamweaver before
    purchasing it and after it initializes a pop up says "java script
    error, critical errors were found in setup, please see setup log
    for details"
    how can i solve this issue? I have updated every possible
    thing i can think of.
    PLEASE HELP...
    Mark

    I don't think you can, but ask on a javascript forum. This is a java forum. Java and javascript are two entirely different languages.

  • Converting flash into java script - please help!

    Our site uses a lot of flash text and flash images, I have
    been told by a friend of a friend that i need to change the way
    flash is embedded into java script - i only know the basics of web
    design and this is me hitting brick wall!
    Maybe someone could help point me in the right direction -
    simply! thank you in advance!!!!!!!!!!!!!!!!!!!!!!!!!!

    which version of dw do you have?
    for background info, google EOLAS activeX lawsuit
    Alan
    Adobe Community Expert, dreamweaver
    http://www.adobe.com/communities/experts/

  • Need flash player 8 and java script enabled to play videos on ipad, need help please.

    need flash player 8 and java script enabled on my ipad in order to view videos.  please help.

    iPads do not directly support Flash.
    You can look for Flash Browsers in the App store for some options to try. Support is not 100%, but maybe one may work for you.  Browsers like Puffin, Skyfire, Photon etc...
    IPads do fully support JavaScript.  Just make sure its turned on under Settings->Safari->Advanced->JavaScript.
    If you require Java, which is completely different to JavaScript, again there are some browsers in the App store that support it.  Search for "Java browsers" in the store.

  • Pdf live cycle  form through sap abap editor to validate user input by java script coding

    I am new to apply a java script in a Adobe form.
    So i need of help that i have 9 page form of HR module i need to verify every blank field and wrong entry field also.
    I look around a lot of code but still i am not able to perform good validation in a Adobe form.
    I am using SAP ABAP editor where i am making through PDF Live cycle FORM & try to put java script validation on the field.
    My problem is that how can i link or configured to Adobe form.
    Here are some event are given "mouseup","validate" or more are given.So how i can do.
    i wrote the code like
    / Get the field value
    var f1 = this.getField("VORNA");----why it is not working.Some thing is wrong?
    var v1 = f1.valueAsString;
    if (v1) {
    } else {
       app.alert("Field: " + f1.name + " is blank.", 1);
    //above code is not working.
    but here we used rawValue() method it works , but it popup message  javascript with window error.
    if( this.rawValue()==' ' || this.rawValue==null)---------this works
    xfa.host.MessageBox("First name is blank!");---------this works
    "VORNA" is "First name" field name binding with this value.
    How we can linked java script file with Adobe form.
    Kindly help me

    You're mixing code for an acroform with code for an XFA form. SInce you're creating the form with LiveCycle Designer, it wold be better if you posted this to the LiveCycle Designer forum, if you haven't already.

  • Pdf live form through sap abap editor to validate user input by java script coding

    I am new to apply a java script in a Adobe form.
    So i need of help that i have 9 page form of HR module i need to verify every blank field and wrong entry field also.
    I look around a lot of code but still i am not able to perform good validation in a Adobe form.
    I am using SAP ABAP editor where i am making through PDF Live cycle FORM & try to put java script validation on the field.
    My problem is that how can i link or configured to Adobe form.
    Here are some event are given "mouseup","validate" or more are given.So how i can do.
    i wrote the code like
    / Get the field value
    var f1 = this.getField("VORNA");----why it is not working.Some thing is wrong?
    var v1 = f1.valueAsString;
    if (v1) {
    } else {
       app.alert("Field: " + f1.name + " is blank.", 1);
    //above code is not working.
    but here we used rawValue() method it works , but it popup message  javascript with window error.
    if( this.rawValue()==' ' || this.rawValue==null)---------this works
    xfa.host.MessageBox("First name is blank!");---------this works
    "VORNA" is "First name" field name binding with this value.
    How we can linked java script file with Adobe form.
    Kindly help me.

    You're mixing code for an acroform with code for an XFA form. SInce you're creating the form with LiveCycle Designer, it wold be better if you posted this to the LiveCycle Designer forum, if you haven't already.

  • Java script Alert-"Adobe Flash Player has stopped a potentially unsafe operation". Can't enable it.

    I am running Windows 7 SP1, Presenter 7.0.0 version 7328 and Powerpoint 2007 (v12.0.6525.1000.)
    My powerpoint file is running in 97-2003 compatibility mode, and I have produced a Presenter project with a link to some web content (a youtube-like video).
    In Firefox browser v23.0.1, I can open the Presenter project from it's html starting point, right click on the SWF presentation as it is running, select global settings, on the advanced tab select trusted location settings, enter the website adress to the youtube-like content, and close the browser, reopen it, and the content launches without a Java script alert.
    The Chrome browser will not do this. (Version 29.0.1547.76 m) (We are not using IE)
    Even setting the web page security permission from the control panel and rebooting will not hold the website in place in the Flash Security settings.
    Even going to the web site and editing directly will not work for chrome - ie, here:
    http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager04.htm l
    By the term "not hold the setting" I mean upon reboot the website is no longer listed as trusted in global settings, nor in Chrome, nor in Flash security settings via Control Panel in W7. It IS listed in Firefox global settings as trusted, and so the content launches from Firefox, as said.
    Firefox is persistant, Chrome is not, and so - is it a buggy Flash Security setting issue? Or a windows/chrome issue? Or my poor local machine....
    Anyone have any ideas?
    /brad

    Hi Chris:
    Thanks for the fast reply!
    I looked. Unfortunately, the people viewing it have their laptops locked down, so cannot access the Internet, Control Panel or Flash Player Settings. So the suggestions there do not help. Anything that you suggest?
    Is there anything I can do at the production end to help?
    Thanks again for your response. It is a bit of an urgent situation, so I really do appreciate it.
    Lavern Wiebe
    <mailto:[email protected]> [email protected]
    Ph: 630.585.5450

  • Flash player not working?  Java Script?

    I can't get any videos to play. Nope, no videos for me. I feel lost without youtube. When ever I try to play any video from the net, it says, "You must either have Java script turned off, or you don't have the latest version of flash." I checked, Java is enabled, and I have downloaded flash, but it still doesn't work. I've also tried deleting related flash files, then re-installing. Still no dice. Can anyone help?

    Hi jcammon,
    I have exactly the same problem: Adobe Flash Player v. 10 works fine in Firefox, but not in Safari. I have tried a number of things, and am becoming increasingly frustrated because nothing so far has worked for me.
    -- I repaired the HD disk from the install disk (the HFS volume needed repair).
    -- I have repaired disk permissions a number of times, before and after installation of v. 10.
    -- I downloaded the archive of various Flash Players v. 9, but they are all for PowerPC-based Macs and I have the Intel version.
    -- I downloaded and installed Flash Player v. 9 but since it's an older version YouTube still doesn't work.
    Is there anything else I can try? Safari is a great browser, but it is all but useless to me if nothing flash-related will load. >.<

  • Flash restricted running scripts or activeX controls

    Hey, can someone give me a hand?
    I read in a different, older forum, that said to use "<!--
    saved from url=(0014)about:internet -->" but how do i put it
    into my flash projects?
    If this is not what i should use then what should i use to
    remove the sign "flash restricted running scripts or activeX
    controls" that pops up when i run the flash on my website.

    I thought that only happened when running flash
    locally.

  • Installation of Adobe Flash 11.7.700.169 fails w/Java script errors

    I am getting very frustrated with Adobe software, it seems that nearly every time I try to update my flash player the update Flash player process fails with a java script error.
    I currently am running Adobe Flash player: 11.6.602.180
    My system is running 32-bit Windows XP, SP3, all patches to date, IE v8.0.6001.18702.
    When I try to install the Adobe Flash player update to 11.7.700.169 the process always fails with the following....
    A pop up to the screen from IE, titled: "Internet Explorer Script Error"
    The  message displayed on the screen is:
       An error has occured on the script on this page.
       Line: 1
       Char: 15965
       Error: Object Expected
      Code: 0
      URL: http://127.0.0.1/app/_js/adobe.js
    Do you want to continue running scripts on this page? <Yes>/<No>
    No matter what choice I make the install fails (choosing yes causes more Script Error messages to appear, before it finally hangs).
    I have followed the steps suggested on the 'Troubleshooting page', yes Active Scripts are enabled within IE
    I also have tried turning off all AV and Firewalls when performing installation, yet I get the same errors.
    Thanks,
    Mark Reynolds

    Download and run the offline installer from http://helpx.adobe.com/flash-player/kb/installation-problems-flash-player-windows.html#mai n-pars_header

  • My safari screen is greyed out, I checked and found a response to this question.  I went to settings and cleared history, cookies, and cache, java script is on and I restarted, screen is still grey, cant touch it to do a thing.  Help!

    my safari screen is greyed out, I checked and found a response to this question.  I went to settings and cleared history, cookies, and cache, java script is on and I restarted, screen is still grey, cant touch it to do a thing.  Help!

    That is usually the fix but try this now.
    Reset the iPad by holding down on the sleep and home buttons at the same time for about 10-15 seconds until the Apple logo appears - ignore the red slider - let go of the buttons. See if that helps.
    You can also try this - quit Safari. From the home screen - Double tap the home button and your recent apps appear the bottom. Tap and hold down on the Safari icon until it wiggles. Tap the minus sign in the upper left corner to close the app. Tap the home button twice. Restart the iPad.
    Message was edited by: Demo

  • I cannot see live cricket there is no any flash player or java script so what I will do for that

    I want to see live cricket but I do not have flash player

    Search the App store for specific Cricket app or one for that broadcasting company. No iOS devices supports Flash
    All iOS devices do support Java Script. However, they do not support Java
    Also, have you looked at the previous discussions listed on the right side of this page under the heading "More Like This"?

  • YouTube and Yahoo problems - Enable Java Script or Download Latest Flash???

    For a number of weeks, I have had problems with browsing certain sites. I initially noticed that some adverts had a connection error on web pages that were displaying their content fine in every other way.
    I then noticed that I couldn't access any page to do with Yahoo (connection error). I assumed that Yahoo was down until I tried to access YouTube where all that is displayed is a white page with all the text from the page in columns down the left hand side.
    There is an error message that tells me to check that Java Script is Enabled or to download the latest Flash Player.
    I have checked Java Script (enabled) and uninstalled / reinstalled latest Adobe Flash, but still have the same issue. I have the same problem with Firefox 2 and 3, and even installed Opera and got the same problem.
    All the forums and support pages I can find don't seem to come up with a definitve answer.
    This is the first REAL issue I have had with my Mac since I have had it and it has never let me down untill now......HELP!!
    Thanks (I hope!!) in advance.

    Could it be a routing problem even though I never used to have this problem with the current router and provider?
    There are also three other laptops using the same router and provider (all PCs), they all have no problems connecting to YouTube, Yahoo, etc.
    Is it possible that a routing problem would only affect my Mac?
    I have tried Safari, Firefox (2 & 3) and Opera. All have same issue.
    I think I have cleared cache, can someone confirm the correct procedure?
    Message was edited by: Lekseon

Maybe you are looking for

  • Local Area Connection - Network cable unplugged

    Hello everybody. I got a problem with my network adapter. When I plug the internet cable to use my cable connection no signal is received from the adapter and my Windows 7 tells me that the cable is not plugged , although it is and now I don't know w

  • How to append the data in a file

    Dear All, i want to continously update one text file that is in myfile.txt using java, for example username:test:password:test like wise how can i append this text with username and password to added in the next next line

  • RFC -File Sync Async bridge RFC Adapter Exception

    Hi I am using sync async bridge to send a response back to rfc. Although there is no error in sxmb_moni as well as the auditlog shows that the response was sent successfully to rfc.. still the RFC adapter gives the following error with no response se

  • Crystal reports graph sort order

    I have 2 fields called fiscal year and fiscal month. Expected sort order - sample values: Fiscal year     Fiscal Month 2011     5 2011     5 2011     6 2011     7 2011     8 2011     9 2011     10 2011     11 2011     12 2012     1 2012     2 2012   

  • I can't see my virtualhost when I deploy my application.

    Hi, Weblogic version: 10.3.6 I followed this article steps by steps, but I can't see virtualHost. Why I can't see my virtualhost when i want deploy my application? http://weblogic-wonders.com/weblogic/2010/11/19/virtual-hosts-configuration-with-weblo