Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2021-21444 Clickjacking vulnerability in SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad), SAP security note 2935791

SAP Note 2935791
SAP Security Note
Medium priority

SAP security note 2935791, "[CVE-2021-21444] Clickjacking vulnerability in SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad)", is a note released on 09.02.2021. Below are the symptom and SAP recommended solution.

ComponentBusiness intelligence solutions > Business intelligence platform > Central Management Console (CMC)
PriorityCorrection with medium priority
TypeSAP Security Note
Version8
StatusReleased for Customer
Released on09.02.2021

Description

Symptom

SAP Business Object allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added XFO header leading to Clickjacking attack.

Solution

This issue is fixed in the patches listed in the “Support Packages & Patches” section below.

For Business Intelligence Platform maintenance schedule and strategy, see the Knowledge Base Article 2144559 in the References section.

Reason and prerequisites

Intermediate URL for BI Launchpad & CMC applications allow the hackers to perform clickjacking attacks. Ensure only a single X-Frame-Options header is present in the response.

CVSS

Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

References

Full note on SAP: SAP Support Launchpad note 2935791

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More