SAP Security Note
Medium priority
SAP security note 2652186, "Denial of Service in B2B Adapters", is a program error note released on 28.08.2018. Below are the symptom and SAP recommended solution.
Description
Symptom
B2B Adapters allow an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
Some well-known impacts of Denial of Service vulnerability are:
- Long response delays and service interruptions, thus degrading the service quality experienced by legitimate users
- Direct impact on availability
Solution
The problem has been resolved by code correction. The archives and the support package stack guide can be found on the SAP Support Portal.
Reason and prerequisites
The problem is caused by a resource exhaustion condition. An attacker can launch a specifically crafted request that causes the process to consume excessive resources. As a result, no other processes can allocate new resources, rendering the system unavailable. This condition can be intentionally provoked by an attacker to cause a denial of service.
CVSS
Score 4.9 Vector: AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
References
- SAP Note 2682573 – TPM: Input help for selecting EDI message type is not working
- SAP Note 2684494 – EDI Separator Adapter does not generate negative CONTRL in case of validation error for EDIFACT or EANCOM messages
Full note on SAP: SAP Support Launchpad note 2652186
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
