Problem Details: JSON Hijacking Possible
Short Text
JSON Hijacking Possible
Long Text
JSON Hijacking is an advanced attack that is similar to Cross-Site
Request Forgery, however unlike CSRF a malicious site is able to obtain
information from the target site. This interception ("hijacking") of
confidential data occurs when a response to a HTTP GET request is
returned in JSON format. JSON Hijacking is a technique that through
overloading the Array or Object constructors in browser scripting
languages with constructors whom intercepts the data. This allows the
malicious site to monitor JSON messages and possible steal sensitive
This policy states that any area of the website or web application that
contains sensitive information can be accessed
Steps for Reconstruction
GET /sapui5/resources/sap/ui/commons/library-preload.json HTTP/1.1
Accept: */*
Pragma: no-cache
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:22.0) Gecko/20100101
Host: apptbouat02.dev.corp.btpn.co.id:8083
Connection: Keep-Alive
X-WIPP: AscVersion=10.20.666.10
X-Scan-Memo: Category="Audit.Attack";
PSID="40DE4CBC47287605971637895DE40131"; SessionType="AuditAttack";
CrawlType="None"; AttackType="None"; OriginatingEngineID="65cee7d3-561f40dc-b5eb-c0b8c2383fcb"; AttackSequence="0"; AttackParamDesc="";
AttackParamIndex="0"; AttackParamSubIndex="0"; CheckId="10733";
Engine="Request+Modify"; Retry="False";
SmartMode="NonServerSpecificOnly"; ThreadId="45";
X-RequestManager-Memo: StateID="263"; sc="1";



If those JSON files can be access by anonymous and there is no encryption for it. you need to make authentication to forbid to unauthorized user or certification which will make possible to encription. My document is what can be possible on SMP side. But you may need to figure it out how to contol security beckend side also. it will be critical problem on your side. I hope it would be helpful to you. I hope you write down or attach every detailed information related to this issue. If I can get any solution or W/A for this message. I will send it to you. This message will contain all about this issue. I will contact to you soon after I analyze this issue Thanks and Best regards.