SAP security note 1500307, “DOS Issue Removed in UI.” Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A potential Denial of Service (DoS) vulnerability exists in MVC within SRM. A malicious user can exploit MVC to render it unavailable, potentially affecting the resources used to serve MVC, leading to a system-wide outage.
Solution
Import the corresponding support package or implement the attached advanced correction manually to address the vulnerability.
Reason and prerequisites
Infinite Loop: A malicious user can trigger a condition causing the process to enter an infinite loop, consuming all available processing time and rendering the machine unresponsive until manually terminated.
Resource Exhaustion: An attacker can send specially crafted requests that consume excessive system resources, preventing other processes from allocating new resources and causing a DoS condition.
Affected components
- SRM 7.0
- SRM 7.01 SP01
- SRM 7.01 SP02
Full note on SAP: SAP Support Launchpad note 1500307
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
