Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2021-21446 Denial of service (DOS) in SAP NetWeaver AS ABAP and ABAP Platform, SAP security note 3000306

SAP Note 3000306
SAP Security Note

SAP security note 3000306, "[CVE-2021-21446] Denial of Service (DoS) in SAP NetWeaver AS ABAP and ABAP Platform", is a note released on January 26, 2021. Below is the SAP recommended solution.

ComponentBC-ABA-LA (Basis Components > ABAP Runtime Environment – ABAP Language Issues Only > Syntax, Compiler, Runtime)
TypeSAP Security Note
Version6
Released onJanuary 26, 2021

Description

Solution

Implement the correction instructions provided in this SAP Note to prohibit the parallel execution of demo examples from the web version of the ABAP Keyword Documentation. This will prevent the DoS vulnerability and ensure meaningful error messages are displayed to users.

Reason and prerequisites

ABAP Server’s and ABAP Platform’s ABAP Keyword Documentation includes demo examples embedded in the documentation. Executing these examples from the web version of the ABAP Keyword Documentation can lock users, resulting in "service not available" experiences.

CVSS

Score 7.5 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Full note on SAP: SAP Support Launchpad note 3000306

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More