Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Cross-Frame Scripting protection in SAP ABAP HTTP logon application, SAP security note 2028904

SAP Note 2028904
Medium priority

SAP security note 2028904, "Cross-Frame Scripting protection in SAP ABAP HTTP logon application", is a program error note released on 26.11.2018. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBC-MID-ICF-LGN
CategoryProgram error
PriorityCorrection with medium priority
StatusReleased for Customer
Released on26.11.2018

Description

Symptom

The standard SAP logon application can be exploited by an attacker to access data entered by legitimate users across different pages of the logon application. This vulnerability leverages browser weaknesses, allowing unauthorized data access despite the Web AS ABAP not being directly vulnerable to XFS attacks. Implementing additional defenses is recommended to mitigate such risks, especially if browser vulnerabilities have not been fully resolved.

Solution

Apply the attached manual correction instructions or import the corresponding support package available here.

CVSS

Score 5.4 Vector: AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N

References

Affected components

  • SAP_BASIS 6.40
  • SAP_BASIS 7.00
  • SAP_BASIS 7.01
  • SAP_BASIS 7.02
  • SAP_BASIS 7.10
  • SAP_BASIS 7.11
  • SAP_BASIS 7.20
  • SAP_BASIS 7.30
  • SAP_BASIS 7.31
  • SAP_BASIS 7.40
  • SAP_BASIS 7.50
  • SAP_BASIS 7.51 to 7.53+

Full note on SAP: SAP Support Launchpad note 2028904

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More