Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Denial of service (DOS) in GWJPO, SAP security note 2604541

SAP Note 2604541
High priority

SAP security note 2604541, "Denial of service (DOS) in GWJPO", is a program error note released on 13.03.2018. Below are the symptom, SAP recommended solution and the affected software components.

ComponentOccasional Platform User > Gateway > Java
CategoryProgram error
PriorityCorrection with high priority
StatusReleased for Customer
Released on13.03.2018

Description

Symptom

SAP Security Note 2604541 addresses a Denial of Service (DoS) vulnerability in GWJPO. This vulnerability allows an attacker to prevent legitimate users from accessing the service by crashing or flooding the service, leading to long response delays, service interruptions, and a direct impact on availability.

Solution

To mitigate this vulnerability, apply the appropriate support package patches for your GWJPO version as listed below.

Ensure that you apply the appropriate patch for your system's GWJPO version to mitigate the DoS vulnerability effectively.

Reason and prerequisites

This vulnerability is associated with CVE-2017-12624 and CVE-2017-3156. The issue arises because GWJPO was using the org.apache.cxf.jaxrs.servlet.CXFNonSpringJaxrsServlet servlet to handle incoming requests, which is vulnerable to the aforementioned CVEs. The solution involves switching to the org.apache.olingo.odata2.core.servlet.ODataServlet, which does not have reported security vulnerabilities.

Affected components

  • GWJPO 7.31
  • GWJPO 7.40
  • GWJPO 7.50

Full note on SAP: SAP Support Launchpad note 2604541

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More