Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Denial of service (DOS) in Internet Sales, SAP security note 2629535

SAP Note 2629535
SAP Security Note
High priority

SAP security note 2629535, "Denial of Service (DoS) Vulnerability in Internet Sales", is a note released on June 13, 2018. Below are the symptom, CVSS score, SAP recommended solution and references.

ComponentCustomer Relationship Management > Internet Sales > Technical Infrastructure (CRM-ISA-TEC)
PriorityHigh priority
TypeSAP Security Note
Version8
StatusReleased for Customer
Released onJune 13, 2018

Description

Symptom

Internet Sales allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. The vulnerability exists in MultipartStream.java in Apache Commons FileUpload before version 1.3.1, as used in Apache Tomcat, JBoss Web, and other products. Under certain conditions, a remote attacker can exploit this to cause a denial of service (DoS) (CVE-2014-0050).

Solution

This security note contains Java corrections for Internet Sales / E-Commerce / Web Channel, where additional request header data validation has been added. Implement the SP Patch Level attached to this note.

For further information about installing Java patches, consult note 877887. Information about the patch strategy can be found in note 1546959.

CVSS

Score 7.3 / 10 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

References

Full note on SAP: SAP Support Launchpad note 2629535

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More