SAP Security Note
Medium priority
SAP security note 2835240, "Clickjacking vulnerability in Cloud Integration Content of SAP Process Integration", is a program error note released on February 9, 2021. Below are the symptom and SAP recommended solution.
Description
Symptom
The vulnerability arises because the Cloud Integration Content of SAP Process Integration does not properly restrict frame objects or UI layers from other applications or domains, resulting in a Clickjacking vulnerability. Successful exploitation of this vulnerability allows attackers to modify user data without authorization.
Solution
The vulnerability has been addressed through the release of specific Support Packages and Patches referenced in this Security Note. Additionally, manual activities are required to fully mitigate the risk:
Enable Clickjacking Protection Framework:
- Follow the manual instructions detailed in SAP Note 2170590 for implementing whitelist services for Clickjacking Framing Protection in AS JAVA.
- Refer to SAP Note 2263656 for enabling whitelist-based Clickjacking Framing Protection in HTMLB Java.
- If running custom JSPs on AS Java, consult SAP Note 2290783 for additional protection measures.
CVSS
Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
References
- SAP Note 2170590 – Whitelist service for Clickjacking Framing Protection in AS JAVA
- SAP Note 2263656 – Whitelist based Clickjacking Framing Protection in HTMLB Java
- SAP Note 2290783 – Whitelist based Clickjacking Framing Protection for Java Server Pages
Full note on SAP: SAP Support Launchpad note 2835240
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
