SAP security note 2243373, “Potential denial of service in BC-WD-JAV”. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can remotely exploit the Webdynpro Java application, rendering it and potentially the resources used to serve Webdynpro Java unavailable.
Solution
A fix is provided to resolve this issue. You can download the fix.
Reason and prerequisites
An attacker can trigger a condition in which the process enters an endless loop, causing it to consume all available processing time. This causes the entire machine to become unresponsive until the process is terminated manually. An attacker can use this flaw to launch a denial-of-service (DoS) attack.
The problem is caused by a resource exhaustion condition. An attacker can launch a specifically crafted request that causes the process to consume excessive resources. As a result, no other processes can allocate new resources, rendering the system unavailable. This condition can be intentionally provoked by an attacker to cause a denial of service.
References
- 2263757 – Getting 404 Error on clicking any link in the NWA application or any WD Java application
- 2206761 – Collective Note: SAP NetWeaver 7.02 SP18 – Application Server Java
Full note on SAP: SAP Support Launchpad note 2243373
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
