SAP security note 2170590, "Whitelist service for Clickjacking Framing Protection in AS JAVA", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Without protection, AS JAVA applications do not safeguard against Clickjacking, allowing potential UI redressing attacks that exploit standard HTML features without needing code vulnerabilities.
Solution
SAP introduces a whitelist-based framework tailored for NetWeaver technologies to mitigate Clickjacking risks.
Reason and prerequisites
Clickjacking is an attack that manipulates the UI to deceive users into performing unintended actions. Traditional protection methods like the X-FRAME-OPTIONS header are inadequate for common NetWeaver integration scenarios, necessitating a specialized solution.
References
- 2319727 – Clickjacking protection framework in SAP Netweaver AS ABAP and AS Java
- 2290783 – Whitelist based Clickjacking Framing Protection for Java Server Pages
- 2286679 – Whitelist Service API required for the Clickjacking Framing Protection in JAVA at the framework or application level
- 2263656 – Whitelist based Clickjacking Framing Protection in HTMLB Java
- 2244161 – Clickjacking Protection in Web Channel Experience Management (WCEM)
- 2169860 – Whitelist based Clickjacking Framing Protection in Web Dynpro Java
- 2169722 – Whitelist based Clickjacking Framing Protection in Enterprise Portal
Affected components
- LM-TOOLS: 7.00 to 7.02
- LMNWAUIFRMRK: 7.10 to 7.50
- LMNWABASICMBEAN: 7.10 to 7.50
Full note on SAP: SAP Support Launchpad note 2170590
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
