Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Whitelist based Clickjacking Framing Protection in CRM-ISA, SAP security note 2297227

SAP Note 2297227

SAP security note 2297227, "Whitelist based Clickjacking Framing Protection in CRM-ISA". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

CRM-ISA is not protected against Clickjacking attacks, which are UI-redressing attacks that trick users into clicking on unintended elements on a webpage.

Solution

Standard Clickjacking protections like the X-FRAME-OPTIONS header are unsuitable for common NetWeaver integration scenarios. SAP provides a whitelist-based framework tailored for NetWeaver technologies.

  • Implement the SP Patch Level attached to this note.
  • Follow the instructions in SAP Note 2319727 for setting up the Clickjacking protection framework.
  • For manual configuration, refer to SAP Note 2327541.

Detailed steps can be found in SAP Note 2327541, which guides you through configuring ClickJacking protection in Web Channel/E-Commerce applications.

Reason and prerequisites

Clickjacking exploits standard HTML functionalities without relying on application code weaknesses. To implement protection:

  • SAP Note 2170590 – Enable and configure ClickJacking solution in SAP NetWeaver Java Server.
  • SAP Note 2263656 – Enable the ClickJacking protection in HTMLB Java.

References

Affected components

  • SAP-CRMJAV, SAP-CRMWEB, SAP-SHRWEB, SAP-SHRJAV, SAP-CRMAPP, SAP-SHRAPP (versions 7.0 to 7.54)

Full note on SAP: SAP Support Launchpad note 2297227

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More