We are facing Clickjacking Vulnerability in SAP NW PO 7.5.
We have checked SAP Note 2170590 and did the following changes.
1) Set the property "ClickjackingProtectionService" and modify the value from "false" to "true".
2) SAP Suggested patches applied in the system. ( XITOOL and XIESR Patch 3)
3) Change parameter to login.block_ext_logon_app_embedding to true (suggested by SAP)
4) Also implement changes provided in PDF of note : 2290783
Still able to click-jacked link "https://<host>:<port>/irj/servlet/prt/portal/prteventname/HtmlbEvent" .
Kindly suggest
Request clarification before answering.
| User | Count |
|---|---|
| 10 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 |
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.