Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential Denial of Service vulnerability in Adobe Document Services, SAP security note 2392719

SAP Note 2392719

SAP security note 2392719, "Potential Denial of Service vulnerability in Adobe Document Services". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Adobe Document Services uses an open source software version – Apache Santuario, for which security vulnerabilities were detected. These allow remote attackers to cause a denial of service (memory consumption) via crafted Document Type Definitions (DTDs), related to signatures.

Solution

Apply the corresponding ADS Support Package (SP) or respective patch.

Reason and prerequisites

This SAP Note is only applicable in case you use:

  • ADS (Adobe Document Services) on NetWeaver 7.30, 7.31, 7.40, or 7.50.

CVSS

Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References

Affected components

  • ADSSAP 7.30
  • ADSSAP 7.31
  • ADSSAP 7.40
  • ADSSAP 7.50

Full note on SAP: SAP Support Launchpad note 2392719

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More