In SAP Enable Now - versions WPB_MANAGER 1.0,...
Moderate severity
Unreviewed
Published
Oct 30, 2023
to the GitHub Advisory Database
•
Updated Nov 8, 2023
Description
Published by the National Vulnerability Database
Oct 30, 2023
Published to the GitHub Advisory Database
Oct 30, 2023
Last updated
Nov 8, 2023
In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-FRAME-OPTIONS response header is not implemented, allowing an unauthenticated attacker to attempt clickjacking, which could result in disclosure or modification of information.
References