SAP security note 2290783, “Whitelist based Clickjacking Framing Protection for Java Server Pages”, is published by SAP for the affected component listed below. The description reproduces the information SAP released for this note.
Description
Java Server Pages technology is not protected against Clickjacking attacks.
CVSS
Score 0
Affected components
- LM-TOOLS | 7.00 | 7.02
- LM-TOOLS | 7.10 | 7.11
- LM-TOOLS | 7.20 | 7.20
- LM-TOOLS | 7.30 | 7.30
- LM-TOOLS | 7.31 | 7.31
- LM-TOOLS | 7.40 | 7.40
- LM-TOOLS | 7.50 | 7.50
- LMNWAUIFRMRK | 7.10 | 7.11
- LMNWAUIFRMRK | 7.20 | 7.20
- LMNWAUIFRMRK | 7.30 | 7.30
- LMNWAUIFRMRK | 7.31 | 7.31
- LMNWAUIFRMRK | 7.40 | 7.40
- LIFECYCLE MGMT TOOLS 7.00 | SP033 | 000001
- LIFECYCLE MGMT TOOLS 7.00 | SP034 | 000000
- LIFECYCLE MGMT TOOLS 7.01 | SP018 | 000001
- LIFECYCLE MGMT TOOLS 7.01 | SP019 | 000000
- LIFECYCLE MGMT TOOLS 7.02 | SP018 | 000002
- LIFECYCLE MGMT TOOLS 7.02 | SP019 | 000000
- LM NWA UI FRAMEWORK 7.10 | SP022 | 000000
- LM NWA UI FRAMEWORK 7.11 | SP017 | 000000
Full note on SAP: SAP Support Launchpad note 2290783
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
