Medium priority
SAP security note 2028904, "Cross-Frame Scripting protection in SAP ABAP HTTP logon application", is a program error note released on 26.11.2018. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The standard SAP logon application can be exploited by an attacker to access data entered by legitimate users across different pages of the logon application. This vulnerability leverages browser weaknesses, allowing unauthorized data access despite the Web AS ABAP not being directly vulnerable to XFS attacks. Implementing additional defenses is recommended to mitigate such risks, especially if browser vulnerabilities have not been fully resolved.
Solution
Apply the attached manual correction instructions or import the corresponding support package available here.
CVSS
Score 5.4 Vector: AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
References
Affected components
- SAP_BASIS 6.40
- SAP_BASIS 7.00
- SAP_BASIS 7.01
- SAP_BASIS 7.02
- SAP_BASIS 7.10
- SAP_BASIS 7.11
- SAP_BASIS 7.20
- SAP_BASIS 7.30
- SAP_BASIS 7.31
- SAP_BASIS 7.40
- SAP_BASIS 7.50
- SAP_BASIS 7.51 to 7.53+
Full note on SAP: SAP Support Launchpad note 2028904
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




