SAP Security Note
HotNews
SAP security note 1562064, “Potential denial of service in http provider of Web AS Java”, is a note released on September 13, 2011. Below are the symptom, SAP recommended solution and references.
Description
Symptom
A malicious user can remotely exploit the HTTP service on the dispatcher process of Web AS Java (J2EE), rendering it and potentially the resources used by the dispatcher process unavailable.
Solution
Update to the latest version of SAP Web AS (J2EE). If updating is not possible, apply one of the patches listed in the SP Patch Level section of the note.
Reason and prerequisites
The issue is caused by a resource exhaustion condition. An attacker can send a specifically crafted request that causes the process to consume excessive resources. Consequently, other processes cannot allocate new resources, rendering the system unavailable. This condition can be intentionally induced by an adversary to cause a Denial of Service.
References
Full note on SAP: SAP Support Launchpad note 1562064
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
