SAP security note 2358849, "Whitelist based Clickjacking Framing Protection in UI theme designer on SAP Portal". Below are the symptom, reason and prerequisites, SAP recommended solution and the affected software components.
Description
Symptom
UI theme designer on SAP Portal lacks protection against Clickjacking attacks.
Solution
SAP provides a whitelist-based framework for protecting against Clickjacking in NetWeaver technologies. This framework ensures that only trusted sources can embed the UI theme designer, mitigating the risk of Clickjacking attacks. For a comprehensive implementation guide, refer to SAP Note 2319727.
Reason and prerequisites
Clickjacking is a UI-redressing attack that leverages standard HTML functionalities to deceive users into performing unintended actions. This attack type does not exploit weaknesses in the application code but rather manipulates the user interface elements.
References
- OWASP Clickjacking
Affected components
- SAPUI5 CLIENT RT AS JAVA 7.30
- SAPUI5 CLIENT RT AS JAVA 7.31
- SAPUI5 CLIENT RT AS JAVA 7.40
- SAPUI5 CLIENT RT AS JAVA 7.50
Full note on SAP: SAP Support Launchpad note 2358849
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
