SAP Security Note
SAP security note 2818963, "Clickjacking vulnerability in Adapter Runtime of SAP Process Integration", is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
The Adapter Runtime of SAP Process Integration does not correctly restrict frame objects or UI layers from other applications or domains, resulting in a Clickjacking vulnerability. Successful exploitation of this vulnerability can lead to unwanted modification of user data.
Solution
The vulnerability has been addressed in the Support Packages and Patches referenced in this SAP Security Note. To fully mitigate the attack, you must enable the clickjacking protection framework by performing the following manual activities in each system where the Note is implemented:
Execute Manual Activities:
- SAP Note 2170590 – Whitelist service for Clickjacking Framing Protection in AS JAVA
- SAP Note 2263656 – Whitelist based Clickjacking Framing Protection in HTMLB Java
- SAP Note 2290783 – Whitelist based Clickjacking Framing Protection for Java Server Pages
CVSS
Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
References
- SAP Note 2170590 – Whitelist service for Clickjacking Framing Protection in AS JAVA
- SAP Note 2263656 – Whitelist based Clickjacking Framing Protection in HTMLB Java
- SAP Note 2290783 – Whitelist based Clickjacking Framing Protection for Java Server Pages
Full note on SAP: SAP Support Launchpad note 2818963
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




