SAP security note 1955742, “Potential Denial of Service in SAML2”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can remotely exploit SAML2, rendering it, and potentially make the resources that are used to serve AS Java unavailable.
Solution
- Not Affected: If SAML2 is not configured on your SAP AS Java, you are not affected by this vulnerability.
- Workaround: You can disable SAML2 functionality by stopping the associated web resources via deploy commands in telnet.
- Fix Availability: Please check the Validity and SP Patch Level sections of this note.
Reason and prerequisites
The problem is caused by a resource exhaustion condition. An attacker can launch a specifically crafted request that causes the process to consume excessive resources. As a result, no other processes can allocate new resources, causing the system to be unavailable. This condition can be intentionally provoked by an attacker to cause a denial of service.
Affected components
- SECURITY-EXT (7.20 – 7.40)
Full note on SAP: SAP Support Launchpad note 1955742
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
