SAP security note 2254425, "Clickjacking vulnerability in SAP Internet Graphics Server". Below are the symptom and SAP recommended solution.
Description
Symptom
IGS allows attackers to embed a malicious page within a frame and hijack user clicks intended for the original (top-level) page, resulting in a Clickjacking vulnerability.
Successful exploitation of this vulnerability leads to unwanted modification of user data.
Solution
Please install the IGS Support Package level as indicated (or higher) in the "Support Packages & Patches".
The X-Frame-Options header is set to DENY in the response returned by the IGS HTTP administration page.
CVSS
Score 4.3 Vector: AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Full note on SAP: SAP Support Launchpad note 2254425
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
