SAP security note 3113593, "Denial of service (DOS) in SAP Commerce". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The library jsoup used in SAP Commerce may be vulnerable to DOS attacks. jsoup is utilized to sanitize various product-related metadata in b2caccelerator. A user with write access to product metadata could exploit this vulnerability.
- Long response delays and service interruptions, degrading the service quality experienced by legitimate users.
- Direct impact on availability.
Solution
SAP Commerce addresses this vulnerability by upgrading jsoup, which does not contain the vulnerability.
The following patch releases address this vulnerability:
- SAP Commerce Cloud Patch Release 2105.4
- SAP Commerce Cloud Patch Release 2011.14
- SAP Commerce Cloud Patch Release 2005.19
- SAP Commerce Cloud Patch Release 1905.35
Software downloads for these or later patches are available in the SAP Support Portal. For information about installing patches, see About Patch Releases.
Workaround: to minimize the impact, restrictions to product-related field length could be implemented to limit the size of inputs sent to jsoup, see Creating Validation Constraints in Backoffice. Please assess the workaround applicability for your SAP landscape prior to implementation. This workaround is a temporary fix and is not a permanent solution; SAP strongly recommends applying the corrections outlined in the security note, which can be done in lieu of the workaround or after the workaround is implemented.
Reason and prerequisites
This vulnerability affects any SAP Commerce installation using the B2C Accelerator.
CVSS
Score 7.5 Vector: CVSS:/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References
- CVE-2021-37714
- B2C Accelerator
- Creating Validation Constraints in Backoffice
Affected components
- HY_COM 1905
- HY_COM 2005
- HY_COM 2105
- HY_COM 2011
Full note on SAP: SAP Support Launchpad note 3113593
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
