SAP Security Note
Medium priority
SAP security note 2307762, “Clickjacking vulnerability in BI Launch Pad”, is a program error note released on 11.10.2016. Below are the symptom and the SAP recommended solution.
Description
Symptom
BI Launch Pad allows an attacker to place a malicious page in a frame and hijack user clicks intended for the original (top-level) page, resulting in a Clickjacking vulnerability.
Successful exploitation of this vulnerability can lead to unwanted modification of user data.
Solution
This issue is fixed in the patches listed in the Support Package & Patches section below.
CVSS
Score 4.3/10 Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Full note on SAP: SAP Support Launchpad note 2307762
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
