Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential Denial of Service in SAML2, SAP security note 1955742

SAP Note 1955742

SAP security note 1955742, “Potential Denial of Service in SAML2”. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An attacker can remotely exploit SAML2, rendering it, and potentially make the resources that are used to serve AS Java unavailable.

Solution

  • Not Affected: If SAML2 is not configured on your SAP AS Java, you are not affected by this vulnerability.
  • Workaround: You can disable SAML2 functionality by stopping the associated web resources via deploy commands in telnet.
  • Fix Availability: Please check the Validity and SP Patch Level sections of this note.

Reason and prerequisites

The problem is caused by a resource exhaustion condition. An attacker can launch a specifically crafted request that causes the process to consume excessive resources. As a result, no other processes can allocate new resources, causing the system to be unavailable. This condition can be intentionally provoked by an attacker to cause a denial of service.

Affected components

  • SECURITY-EXT (7.20 – 7.40)

Full note on SAP: SAP Support Launchpad note 1955742

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More