Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6240 Denial of service (DOS) in SAP NetWeaver Application Server ABAP (Web Dynpro ABAP), SAP security note 2856923

SAP Note 2856923

SAP security note 2856923, "[CVE-2020-6240] Denial of service (DOS) in SAP NetWeaver Application Server ABAP (Web Dynpro ABAP)". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP NetWeaver Application Server ABAP (Web Dynpro ABAP) is affected by a Denial of Service (DoS) vulnerability identified as CVE-2020-6240. An attacker can exploit this vulnerability to prevent legitimate users from accessing services by either crashing or flooding the service. This results in long response delays and service interruptions, directly impacting the availability of the system.

  • Service Interruptions: legitimate users may experience degraded service quality due to long response delays.
  • Availability Issues: direct impact on the system’s availability, hindering business operations.

Solution

To mitigate this vulnerability, implement the correction instructions provided in SAP Security Note 2856923. This involves reducing resource consumption in specific situations to prevent service disruptions. Implementing this security note is crucial for maintaining the stability and availability of your SAP systems.

CVSS

Score 5.3 Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References

Affected components

  • SAP_UI: Versions 750, 752, 753, 754
  • SAP_BASIS: Versions 700-702, 710-711, 730-731, 804

Full note on SAP: SAP Support Launchpad note 2856923

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More