High priority
SAP security note 2604541, "Denial of service (DOS) in GWJPO", is a program error note released on 13.03.2018. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 2604541 addresses a Denial of Service (DoS) vulnerability in GWJPO. This vulnerability allows an attacker to prevent legitimate users from accessing the service by crashing or flooding the service, leading to long response delays, service interruptions, and a direct impact on availability.
Solution
To mitigate this vulnerability, apply the appropriate support package patches for your GWJPO version as listed below.
Ensure that you apply the appropriate patch for your system's GWJPO version to mitigate the DoS vulnerability effectively.
Reason and prerequisites
This vulnerability is associated with CVE-2017-12624 and CVE-2017-3156. The issue arises because GWJPO was using the org.apache.cxf.jaxrs.servlet.CXFNonSpringJaxrsServlet servlet to handle incoming requests, which is vulnerable to the aforementioned CVEs. The solution involves switching to the org.apache.olingo.odata2.core.servlet.ODataServlet, which does not have reported security vulnerabilities.
Affected components
- GWJPO 7.31
- GWJPO 7.40
- GWJPO 7.50
Full note on SAP: SAP Support Launchpad note 2604541
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
