Skip links
Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Whitelist based Clickjacking Framing Protection in CRM-ISA, SAP security note 2297227

Description

CRM-ISA running on JSP technology is not protected against Clickjacking attacks.

Available fix and Supported packages

  • SAP-CRMJAV | 700 | 700
  • SAP-CRMJAV | 701 | 701
  • SAP-CRMJAV | 702 | 702
  • SAP-CRMJAV | 731 | 731
  • SAP-CRMJAV | 730 | 730
  • SAP-CRMJAV | 732 | 732
  • SAP-CRMJAV | 733 | 733
  • SAP-CRMJAV | 754 | 754
  • SAP-CRMWEB | 700 | 700
  • SAP-CRMWEB | 701 | 701
  • SAP-CRMWEB | 702 | 702
  • SAP-CRMWEB | 731 | 731
  • SAP-CRMWEB | 730 | 730
  • SAP-CRMWEB | 732 | 732
  • SAP-CRMWEB | 733 | 733
  • SAP-CRMWEB | 754 | 754
  • SAP-SHRWEB | 700 | 700
  • SAP-SHRWEB | 701 | 701
  • SAP-SHRWEB | 702 | 702
  • SAP-SHRWEB | 731 | 731
  • CRM JAVA APPLICATIONS 7.0 | SP012 | 000144
  • CRM JAVA APPLICATIONS 7.01 | SP009 | 000145
  • CRM JAVA APPLICATIONS 7.02 | SP004 | 000165
  • CRM JAVA APPLICATIONS 7.30 | SP012 | 000145
  • CRM JAVA APPLICATIONS 7.31 | SP009 | 000148
  • CRM JAVA APPLICATIONS 7.32 | SP004 | 000150
  • CRM JAVA APPLICATIONS 7.33 | SP000 | 000106
  • CRM JAVA APPLICATIONS 7.54 | SP001 | 000009
  • CRM JAVA COMPONENTS 7.0 | SP012 | 000144
  • CRM JAVA COMPONENTS 7.01 | SP009 | 000145
  • CRM JAVA COMPONENTS 7.02 | SP004 | 000165
  • CRM JAVA COMPONENTS 7.30 | SP012 | 000145
  • CRM JAVA COMPONENTS 7.31 | SP009 | 000148
  • CRM JAVA COMPONENTS 7.32 | SP004 | 000150
  • CRM JAVA COMPONENTS 7.33 | SP000 | 000106
  • CRM JAVA COMPONENTS 7.54 | SP001 | 000009
  • CRM JAVA WEB COMPONENTS 7.0 | SP012 | 000144
  • CRM JAVA WEB COMPONENTS 7.01 | SP009 | 000145
  • CRM JAVA WEB COMPONENTS 7.02 | SP004 | 000165
  • CRM JAVA WEB COMPONENTS 7.30 | SP012 | 000145

Affected component

    CRM-ISA
    Internet Sales

CVSS

Score: 0

PoC

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/2297227

TAGS

#UI-redressing-attack
#Clickjacking
#Framing-Protection
#Framing
#IFrame
#UI-Redressing
#Clickjacking-Whitelist
#X-FRAME-OPTIONS
#AS-JAVA
#JSP
#
#Internet-Sales
#isa
#ECo
#E-Commerce
#E-Commerce
#WebChannel
#Web-Channel
#EHP
#CRM
#ERP
#r3
#r\3
#r/3
#ECC
#B2B
#Business-to-Business
#Business-to-Business
#B2C
#Business-to-Customer
#Business-to-Customer
#isauseradm
#isa-user-adm
#user-admin
#useradmin
#isa-useradm
#isauser
#user-administration
#shopadmin
#shop-admin
#shop-administrator
#ICSS_B2B
#ICSS-B2B
#Internet-Customer-Self-Service-for-Business-to-Business
#Business-to-Business
#ICSS_B2C
#ICSS-B2C
#Internet-Customer-Self-Service-for-Business-to-Customer
#Business-to-Customer
#AVW
#Auction-via-Web
#IPC
#pricing
#JSP
#JSP-UI

More to explorer

Special offer for SAP Security Udemy course!

$ 9.99

Join “SAP Security Core Concepts and Security Administration” which is part of the Blackhat course series.