Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Clickjacking issue in CMC- Security Issue, SAP security note 2198329

SAP Note 2198329
SAP Security Note
Medium priority

SAP security note 2198329, "Clickjacking Issue in CMC", is a program error note released on 23.06.2016. Below are the symptom, SAP recommended solution and reason and prerequisites.

ComponentBusiness intelligence solutions > Business intelligence platform > Central Management Console (CMC)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on23.06.2016
LanguageEnglish

Description

Symptom

A Cross-Frame Scripting (XFS) vulnerability can allow an attacker to load the vulnerable application inside an HTML iframe tag on a malicious page. The attacker could use this weakness to devise a Clickjacking attack to conduct phishing, frame sniffing, social engineering, or Cross-Site Request Forgery attacks. With this, information displayed in CMC could be compromised without authorization.

Solution

The issue has been fixed in the patches listed in the Support Packages & Patches section below.

For Business Intelligence Platform maintenance schedule and strategy, see Knowledge Base Article 2144559.

Reason and prerequisites

The response header for Central Management Console (CMC) did not have the XFRAME set to SAMEORIGIN, which can be exploited to capture information displayed in CMC.

Full note on SAP: SAP Support Launchpad note 2198329

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More