SAP Security Note
SAP security note 3000306, "[CVE-2021-21446] Denial of Service (DoS) in SAP NetWeaver AS ABAP and ABAP Platform", is a note released on January 26, 2021. Below is the SAP recommended solution.
Description
Solution
Implement the correction instructions provided in this SAP Note to prohibit the parallel execution of demo examples from the web version of the ABAP Keyword Documentation. This will prevent the DoS vulnerability and ensure meaningful error messages are displayed to users.
Reason and prerequisites
ABAP Server’s and ABAP Platform’s ABAP Keyword Documentation includes demo examples embedded in the documentation. Executing these examples from the web version of the ABAP Keyword Documentation can lock users, resulting in "service not available" experiences.
CVSS
Score 7.5 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Full note on SAP: SAP Support Launchpad note 3000306
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
