Description
A Cross-Frame Scripting (XFS) vulnerability can allow an attacker to load the vulnerable application inside an HTML iframe tag
on a malicious page. The attacker could use this weakness to devise a Clickjacking attack to conduct phishing, frame sniffing,
social engineering or Cross-Site Request Forgery attacks. With this , information displayed in CMC could be compromised without authorization.
Available fix and Supported packages
- ENTERPRISE | 4.0 | 4.0
- ENTERPRISE | 410 | 410
- ENTERPRISE | 420 | 420
- SBOP BI PLATFORM SERVERS 4.0 | SP010 | 000010
- SBOP BI PLATFORM SERVERS 4.0 | SP011 | 000005
- SBOP BI PLATFORM SERVERS 4.0 | SP012 | 000000
- SBOP BI PLATFORM SERVERS 4.1 | SP004 | 000012
- SBOP BI PLATFORM SERVERS 4.1 | SP005 | 000009
- SBOP BI PLATFORM SERVERS 4.1 | SP007 | 000000
Affected component
- BI-BIP-CMC
Central Management Console (CMC)
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/2198329