SAP Security Note
Medium priority
SAP security note 2824209, "Clickjacking vulnerability in SAP Process Integration (Integration Builder Framework)", is a program error note released on 10.11.2020. Below are the symptom and SAP recommended solution.
Description
Symptom
The Integration Builder Framework of SAP Process Integration does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, resulting in a Clickjacking vulnerability.
An attacker who successfully exploited this vulnerability could view and modify user data.
Solution
The vulnerability has been fixed with the Support Packages and Patches referenced by this SAP Security Note.
Reason and prerequisites
An appropriate clickjacking protection for JSPs of the Integration Builder Framework was missing.
CVSS
Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
References
- SAP Note 2290783 – Whitelist based Clickjacking Framing Protection for Java Server Pages
- SAP Note 2263656 – Whitelist based Clickjacking Framing Protection in HTMLB Java
- SAP Note 2170590 – Whitelist service for Clickjacking Framing Protection in AS JAVA
- Side effect: SAP Note 2892190 – Access to Additional Information section on index page is allowed with limited User Roles
Full note on SAP: SAP Support Launchpad note 2824209
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
