SAP Security Note
High priority
SAP security note 2629535, "Denial of Service (DoS) Vulnerability in Internet Sales", is a note released on June 13, 2018. Below are the symptom, CVSS score, SAP recommended solution and references.
Description
Symptom
Internet Sales allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. The vulnerability exists in MultipartStream.java in Apache Commons FileUpload before version 1.3.1, as used in Apache Tomcat, JBoss Web, and other products. Under certain conditions, a remote attacker can exploit this to cause a denial of service (DoS) (CVE-2014-0050).
Solution
This security note contains Java corrections for Internet Sales / E-Commerce / Web Channel, where additional request header data validation has been added. Implement the SP Patch Level attached to this note.
For further information about installing Java patches, consult note 877887. Information about the patch strategy can be found in note 1546959.
CVSS
Score 7.3 / 10 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
References
- CVE-2014-0050
- SAP Note 877887 – Installing Patches for CRM Java Components and FSCM BD
- SAP Note 1546959 – Patch strategies for SAP E-Commerce solutions
Full note on SAP: SAP Support Launchpad note 2629535
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
