cancel
Showing results for 
Search instead for 
Did you mean: 

Click Jacking

06-26-2019 12:32 PM
397 views 0 comments
0 Likes
SAP Managed Tags
Subscribe

We are facing Clickjacking Vulnerability in SAP NW PO 7.5.

We have checked SAP Note 2170590 and did the following changes.

1) Set the property "ClickjackingProtectionService" and modify the value from "false" to "true".
2) SAP Suggested patches applied in the system. ( XITOOL and XIESR Patch 3)
3) Change parameter to login.block_ext_logon_app_embedding to true (suggested by SAP)
4) Also implement changes provided in PDF of note : 2290783

Still able to click-jacked link "https://<host>:<port>/irj/servlet/prt/portal/prteventname/HtmlbEvent" .

Kindly suggest

0 Likes

Accepted Solutions (0)

Answers (0)