Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Clickjacking vulnerability in BI Launch Pad, SAP security note 2307762

SAP Note 2307762
SAP Security Note
Medium priority

SAP security note 2307762, “Clickjacking vulnerability in BI Launch Pad”, is a program error note released on 11.10.2016. Below are the symptom and the SAP recommended solution.

ComponentBusiness intelligence solutions > Business intelligence platform > InfoView, BI launch pad
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on11.10.2016
LanguageEnglish

Description

Symptom

BI Launch Pad allows an attacker to place a malicious page in a frame and hijack user clicks intended for the original (top-level) page, resulting in a Clickjacking vulnerability.

Successful exploitation of this vulnerability can lead to unwanted modification of user data.

Solution

This issue is fixed in the patches listed in the Support Package & Patches section below.

CVSS

Score 4.3/10 Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Full note on SAP: SAP Support Launchpad note 2307762

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More