Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Whitelist based Clickjacking Framing Protection for Java Server Pages, SAP security note 2290783

SAP Note 2290783SAP Security Note

SAP security note 2290783, “Whitelist based Clickjacking Framing Protection for Java Server Pages”, is published by SAP for the affected component listed below. The description reproduces the information SAP released for this note.

ComponentBC-JAS-WEB Web Container, HTTP, JavaMail, Servlets

Description

Java Server Pages technology is not protected against Clickjacking attacks.

CVSS

Score 0

Affected components

  • LM-TOOLS | 7.00 | 7.02
  • LM-TOOLS | 7.10 | 7.11
  • LM-TOOLS | 7.20 | 7.20
  • LM-TOOLS | 7.30 | 7.30
  • LM-TOOLS | 7.31 | 7.31
  • LM-TOOLS | 7.40 | 7.40
  • LM-TOOLS | 7.50 | 7.50
  • LMNWAUIFRMRK | 7.10 | 7.11
  • LMNWAUIFRMRK | 7.20 | 7.20
  • LMNWAUIFRMRK | 7.30 | 7.30
  • LMNWAUIFRMRK | 7.31 | 7.31
  • LMNWAUIFRMRK | 7.40 | 7.40
  • LIFECYCLE MGMT TOOLS 7.00 | SP033 | 000001
  • LIFECYCLE MGMT TOOLS 7.00 | SP034 | 000000
  • LIFECYCLE MGMT TOOLS 7.01 | SP018 | 000001
  • LIFECYCLE MGMT TOOLS 7.01 | SP019 | 000000
  • LIFECYCLE MGMT TOOLS 7.02 | SP018 | 000002
  • LIFECYCLE MGMT TOOLS 7.02 | SP019 | 000000
  • LM NWA UI FRAMEWORK 7.10 | SP022 | 000000
  • LM NWA UI FRAMEWORK 7.11 | SP017 | 000000

Full note on SAP: SAP Support Launchpad note 2290783

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More