Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Whitelist based Clickjacking Framing Protection in UI theme designer on SAP Portal, SAP security note 2358849

SAP Note 2358849

SAP security note 2358849, "Whitelist based Clickjacking Framing Protection in UI theme designer on SAP Portal". Below are the symptom, reason and prerequisites, SAP recommended solution and the affected software components.

Description

Symptom

UI theme designer on SAP Portal lacks protection against Clickjacking attacks.

Solution

SAP provides a whitelist-based framework for protecting against Clickjacking in NetWeaver technologies. This framework ensures that only trusted sources can embed the UI theme designer, mitigating the risk of Clickjacking attacks. For a comprehensive implementation guide, refer to SAP Note 2319727.

Reason and prerequisites

Clickjacking is a UI-redressing attack that leverages standard HTML functionalities to deceive users into performing unintended actions. This attack type does not exploit weaknesses in the application code but rather manipulates the user interface elements.

References

  • OWASP Clickjacking

Affected components

  • SAPUI5 CLIENT RT AS JAVA 7.30
  • SAPUI5 CLIENT RT AS JAVA 7.31
  • SAPUI5 CLIENT RT AS JAVA 7.40
  • SAPUI5 CLIENT RT AS JAVA 7.50

Full note on SAP: SAP Support Launchpad note 2358849

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More