Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Whitelist service for Clickjacking Framing Protection in AS JAVA, SAP security note 2170590

SAP Note 2170590

SAP security note 2170590, "Whitelist service for Clickjacking Framing Protection in AS JAVA", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Without protection, AS JAVA applications do not safeguard against Clickjacking, allowing potential UI redressing attacks that exploit standard HTML features without needing code vulnerabilities.

Solution

SAP introduces a whitelist-based framework tailored for NetWeaver technologies to mitigate Clickjacking risks.

Reason and prerequisites

Clickjacking is an attack that manipulates the UI to deceive users into performing unintended actions. Traditional protection methods like the X-FRAME-OPTIONS header are inadequate for common NetWeaver integration scenarios, necessitating a specialized solution.

References

Affected components

  • LM-TOOLS: 7.00 to 7.02
  • LMNWAUIFRMRK: 7.10 to 7.50
  • LMNWABASICMBEAN: 7.10 to 7.50

Full note on SAP: SAP Support Launchpad note 2170590

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More