SAP security note 2297227, "Whitelist based Clickjacking Framing Protection in CRM-ISA". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
CRM-ISA is not protected against Clickjacking attacks, which are UI-redressing attacks that trick users into clicking on unintended elements on a webpage.
Solution
Standard Clickjacking protections like the X-FRAME-OPTIONS header are unsuitable for common NetWeaver integration scenarios. SAP provides a whitelist-based framework tailored for NetWeaver technologies.
- Implement the SP Patch Level attached to this note.
- Follow the instructions in SAP Note 2319727 for setting up the Clickjacking protection framework.
- For manual configuration, refer to SAP Note 2327541.
Detailed steps can be found in SAP Note 2327541, which guides you through configuring ClickJacking protection in Web Channel/E-Commerce applications.
Reason and prerequisites
Clickjacking exploits standard HTML functionalities without relying on application code weaknesses. To implement protection:
- SAP Note 2170590 – Enable and configure ClickJacking solution in SAP NetWeaver Java Server.
- SAP Note 2263656 – Enable the ClickJacking protection in HTMLB Java.
References
- Clickjacking Details – OWASP
- SAP Note 2170590
- SAP Note 2263656
- SAP Note 2319727
- SAP Note 2327541
- SAP Note 877887
- SAP Note 1546959
Affected components
- SAP-CRMJAV, SAP-CRMWEB, SAP-SHRWEB, SAP-SHRJAV, SAP-CRMAPP, SAP-SHRAPP (versions 7.0 to 7.54)
Full note on SAP: SAP Support Launchpad note 2297227
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
