SAP security note 2856923, "[CVE-2020-6240] Denial of service (DOS) in SAP NetWeaver Application Server ABAP (Web Dynpro ABAP)". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP NetWeaver Application Server ABAP (Web Dynpro ABAP) is affected by a Denial of Service (DoS) vulnerability identified as CVE-2020-6240. An attacker can exploit this vulnerability to prevent legitimate users from accessing services by either crashing or flooding the service. This results in long response delays and service interruptions, directly impacting the availability of the system.
- Service Interruptions: legitimate users may experience degraded service quality due to long response delays.
- Availability Issues: direct impact on the system’s availability, hindering business operations.
Solution
To mitigate this vulnerability, implement the correction instructions provided in SAP Security Note 2856923. This involves reducing resource consumption in specific situations to prevent service disruptions. Implementing this security note is crucial for maintaining the stability and availability of your SAP systems.
CVSS
Score 5.3 Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
References
- Information Disclosure in Web Dynpro ABAP applications
- Cross-Site Request Forgery (CSRF) vulnerability in SAP Web Dynpro ABAP
Affected components
- SAP_UI: Versions 750, 752, 753, 754
- SAP_BASIS: Versions 700-702, 710-711, 730-731, 804
Full note on SAP: SAP Support Launchpad note 2856923
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



