SAP security note 2315788, "Denial of service (DOS) in Enterprise Portal: Federated Portal Network", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Enterprise Portal -> Federated Portal Network allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
Some well-known impacts of Denial of Service vulnerability are:
- Long response delays and service interruptions, thus degrading the service quality experienced by legitimate users
- Direct impact on availability
Solution
Added restriction to approved objects only.
Under the "Support Packages & Patches" tab within this note, you can check for the appropriate SP & Patch level fixing this issue.
Reason and prerequisites
Program error.
CVSS
Score 4.9 Vector: AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
References
This note refers to
Affected components
- EP-RUNTIME 7.20
- EP-RUNTIME 7.30
- EP-RUNTIME 7.31
- EP-RUNTIME 7.40
- EP-RUNTIME 7.50
Full note on SAP: SAP Support Launchpad note 2315788
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
