Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Denial of Service in B2B Adapters, SAP security note 2652186

SAP Note 2652186
SAP Security Note
Medium priority

SAP security note 2652186, "Denial of Service in B2B Adapters", is a program error note released on 28.08.2018. Below are the symptom and SAP recommended solution.

ComponentBC-XI-CON-B2B
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released on28.08.2018
LanguageEnglish

Description

Symptom

B2B Adapters allow an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

Some well-known impacts of Denial of Service vulnerability are:

  • Long response delays and service interruptions, thus degrading the service quality experienced by legitimate users
  • Direct impact on availability

Solution

The problem has been resolved by code correction. The archives and the support package stack guide can be found on the SAP Support Portal.

Reason and prerequisites

The problem is caused by a resource exhaustion condition. An attacker can launch a specifically crafted request that causes the process to consume excessive resources. As a result, no other processes can allocate new resources, rendering the system unavailable. This condition can be intentionally provoked by an attacker to cause a denial of service.

CVSS

Score 4.9 Vector: AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

References

  • SAP Note 2682573 – TPM: Input help for selecting EDI message type is not working
  • SAP Note 2684494 – EDI Separator Adapter does not generate negative CONTRL in case of validation error for EDIFACT or EANCOM messages

Full note on SAP: SAP Support Launchpad note 2652186

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More