SAP Security Note
Medium priority
SAP security note 2198329, "Clickjacking Issue in CMC", is a program error note released on 23.06.2016. Below are the symptom, SAP recommended solution and reason and prerequisites.
Description
Symptom
A Cross-Frame Scripting (XFS) vulnerability can allow an attacker to load the vulnerable application inside an HTML iframe tag on a malicious page. The attacker could use this weakness to devise a Clickjacking attack to conduct phishing, frame sniffing, social engineering, or Cross-Site Request Forgery attacks. With this, information displayed in CMC could be compromised without authorization.
Solution
The issue has been fixed in the patches listed in the Support Packages & Patches section below.
For Business Intelligence Platform maintenance schedule and strategy, see Knowledge Base Article 2144559.
Reason and prerequisites
The response header for Central Management Console (CMC) did not have the XFRAME set to SAMEORIGIN, which can be exploited to capture information displayed in CMC.
Full note on SAP: SAP Support Launchpad note 2198329
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
