Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Clickjacking vulnerability in Cloud Integration Content of SAP Process Integration, SAP security note 2835240

SAP Note 2835240
SAP Security Note
Medium priority

SAP security note 2835240, "Clickjacking vulnerability in Cloud Integration Content of SAP Process Integration", is a program error note released on February 9, 2021. Below are the symptom and SAP recommended solution.

CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onFebruary 9, 2021
LanguageEnglish

Description

Symptom

The vulnerability arises because the Cloud Integration Content of SAP Process Integration does not properly restrict frame objects or UI layers from other applications or domains, resulting in a Clickjacking vulnerability. Successful exploitation of this vulnerability allows attackers to modify user data without authorization.

Solution

The vulnerability has been addressed through the release of specific Support Packages and Patches referenced in this Security Note. Additionally, manual activities are required to fully mitigate the risk:

Enable Clickjacking Protection Framework:

  • Follow the manual instructions detailed in SAP Note 2170590 for implementing whitelist services for Clickjacking Framing Protection in AS JAVA.
  • Refer to SAP Note 2263656 for enabling whitelist-based Clickjacking Framing Protection in HTMLB Java.
  • If running custom JSPs on AS Java, consult SAP Note 2290783 for additional protection measures.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

References

Full note on SAP: SAP Support Launchpad note 2835240

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More