Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0305 Clickjacking vulnerability in Integration Builder Framework of SAP NetWeaver Process Integration, SAP security note 2755502

SAP Note 2755502

SAP security note 2755502, "[CVE-2019-0305] Clickjacking vulnerability in Integration Builder Framework of SAP NetWeaver Process Integration", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A clickjacking vulnerability exists in the Java Server Pages (JSPs) provided by the PI Integration Builder Web UI of SAP NetWeaver Process Integration. The vulnerability arises because the JSPs do not properly restrict frame objects or UI layers from other applications or domains. Successful exploitation can lead to unwanted modification of user data through UI redressing attacks.

  • CVE Identifier: CVE-2019-0305
  • Impact: Low Integrity Impact (I:L) with a CVSS score of 4.3

Solution

To mitigate this vulnerability, apply the Support Packages and Patches referenced in this SAP Security Note. Additionally, enable the SAP ClickJacking Protection Framework. Detailed instructions for enabling the framework can be found in SAP Note 2290783.

CVSS

Score 4.3 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

References

Affected components

  • SAP_XIESR 7.10 to 7.50
  • SAP_XITOOL 7.10 to 7.50

Full note on SAP: SAP Support Launchpad note 2755502

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More