Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential denial of service in BC-WD-JAV, SAP security note 2243373

SAP Note 2243373

SAP security note 2243373, “Potential denial of service in BC-WD-JAV”. Below are the symptom and SAP recommended solution.

Description

Symptom

An attacker can remotely exploit the Webdynpro Java application, rendering it and potentially the resources used to serve Webdynpro Java unavailable.

Solution

A fix is provided to resolve this issue. You can download the fix.

Reason and prerequisites

An attacker can trigger a condition in which the process enters an endless loop, causing it to consume all available processing time. This causes the entire machine to become unresponsive until the process is terminated manually. An attacker can use this flaw to launch a denial-of-service (DoS) attack.

The problem is caused by a resource exhaustion condition. An attacker can launch a specifically crafted request that causes the process to consume excessive resources. As a result, no other processes can allocate new resources, rendering the system unavailable. This condition can be intentionally provoked by an attacker to cause a denial of service.

References

Full note on SAP: SAP Support Launchpad note 2243373

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More