SAP Security Note
Medium priority
SAP security note 2935791, "[CVE-2021-21444] Clickjacking vulnerability in SAP Business Objects Business Intelligence Platform (CMC and BI Launchpad)", is a note released on 09.02.2021. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP Business Object allows multiple X-Frame-Options headers entries in the response headers, which may not be predictably treated by all user agents. This could, as a result, nullify the added XFO header leading to Clickjacking attack.
Solution
This issue is fixed in the patches listed in the “Support Packages & Patches” section below.
For Business Intelligence Platform maintenance schedule and strategy, see the Knowledge Base Article 2144559 in the References section.
Reason and prerequisites
Intermediate URL for BI Launchpad & CMC applications allow the hackers to perform clickjacking attacks. Ensure only a single X-Frame-Options header is present in the response.
CVSS
Score 5.4 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
References
Full note on SAP: SAP Support Launchpad note 2935791
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
