Security Note: Session Forwarding by URL

[] [] [] [] [] [] [] []

Symptom
An URL, which has been received for example by e-mail, enables a user to connect with the SAP system.
Other terms
Security vulnerability, Session Riding
Reason and Prerequisites
The system is not configured for the HTTP Security Session, see transaction SICF_SESSIONS.
The application, which can be accessed, uses the “stateful-http-communication”. This means the session with the backend is kept [...]

Make number of contexts for each user configurable (ESID)

[] [] [] [] [] [] [] [] [] [] [] [] [] [] [] []

Symptom
If you open more than six windows from the Enterprise Portal, the system may issue the error message “Session timeout” in one or several windows that you have previously opened.
Other terms
ESID, external session identifier, external, session id, session timeout, ep, EP, Enterprise Portal, wd, WD, Web Dynpro
Reason and Prerequisites
This error occurs because no more [...]

Startup Framework patch collection PC-10

[] [] [] [] [] [] [] [] []

Symptom
The Startup Framework (SF) 7.02, 7.10, 7.11, and 7.20 contains errors.
Other terms
Startup Framework, JStart, web session, ShmWebSession
Reason and Prerequisites
This note documents changes in patch collection 10 for the Startup Framework.
Solution
This patch collection contains fixes for the following errors:
Small response messages from the JStart Instance Controller to the Start Service are not correctly initialized and [...]