SAP security note 2399804, "Denial of service (DOS) in Visual Composer", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The devserver package of Visual Composer deserializes a malicious object that may cause legitimate users accessing a service, either by crashing or flooding the service.
Solution
When the stream is read, the class description of the serialized object appears before the object itself. The class description can be checked, and it can be decided whether to continue reading the stream.
Reason and prerequisites
Reason: Malformed data or unexpected data could be used to abuse application logic, deny service, or execute arbitrary code when deserialized. These internal resources can be disclosed in the response to the request or can be used to perform a denial of service attack on the parsing system, rendering application content temporarily unavailable.
Prerequisites: You are running the Visual Composer application created in CE versions.
CVSS
Score 7.5 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References
Affected components
- VCFRAMEWORK 7.10 to 7.11
- VCFRAMEWORK 7.20
- VCFRAMEWORK 7.30 to 7.31
- VCFRAMEWORK 7.40
- VCFRAMEWORK 7.50
Full note on SAP: SAP Support Launchpad note 2399804
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




