SAP security note 2236258, "Missing XML Validation vulnerability in Adobe Document Services". Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can remotely exploit Adobe Document Services, making it and potentially the resources used to serve it unavailable. Impacts from the missing XML Validation vulnerability include arbitrary file retrieval from the server and denial-of-service conditions in successful exploits.
Solution
Apply the corresponding SAP NetWeaver ADS Support Package or Patch. It is also recommended to apply the latest SAPJVM patch.
Reason and prerequisites
The issue is caused by a resource exhaustion condition. An attacker can send a specifically crafted request that causes the process to consume excessive resources, preventing other processes from allocating new resources and rendering the system unavailable.
CVSS
Score 5.5 / 10 Vector: AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
References
Full note on SAP: SAP Support Launchpad note 2236258
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
