SAP security note 2296909, “Denial of service (DOS) vulnerability in BPM”, is a note released on 09.08.2016. Below are the symptom and SAP recommended solution.
Description
Symptom
The BPM component allows an attacker to prevent legitimate users from accessing a service by either crashing or flooding the service. This Denial of Service (DoS) vulnerability can lead to:
- Long response delays and service interruptions, degrading service quality for legitimate users.
- Direct impact on availability.
Solution
Resolving of external entities has been disabled during XML parsing. To correct this issue:
- Apply the patch matching your support package version as listed in the Support Package Patches section below.
- Follow the instructions in the SAP NetWeaver Support Package Stack Guide.
CVSS
Score 6.4 Vector: AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H
Full note on SAP: SAP Support Launchpad note 2296909
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
