Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Missing XML Validation vulnerability in Adobe Document Services, SAP security note 2236258

SAP Note 2236258

SAP security note 2236258, "Missing XML Validation vulnerability in Adobe Document Services". Below are the symptom and SAP recommended solution.

Description

Symptom

An attacker can remotely exploit Adobe Document Services, making it and potentially the resources used to serve it unavailable. Impacts from the missing XML Validation vulnerability include arbitrary file retrieval from the server and denial-of-service conditions in successful exploits.

Solution

Apply the corresponding SAP NetWeaver ADS Support Package or Patch. It is also recommended to apply the latest SAPJVM patch.

Reason and prerequisites

The issue is caused by a resource exhaustion condition. An attacker can send a specifically crafted request that causes the process to consume excessive resources, preventing other processes from allocating new resources and rendering the system unavailable.

CVSS

Score 5.5 / 10 Vector: AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L

References

Full note on SAP: SAP Support Launchpad note 2236258

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More