Description
Symptom
The library jsoup used in SAP Commerce may be vulnerable to DOS attacks. jsoup is used to sanitize various product related metadata in b2caccelerator. A user with write access to product metadata could exploit this vulnerability.
The impacts of the vulnerability are –
- Long response delays and service interruptions, thus degrading the service quality experienced by legitimate users
- Direct impact on availability
Other Terms
DoS, DDoS, Distributed Denial of Service, Uncontrolled Resource consumption, Resource Exhaustion, CVE-2021-37714
Reason and Prerequisites
This vulnerability affects any SAP Commerce installation using the B2C Accelerator.
Solution
SAP Commerce addresses this vulnerability by upgrading jsoup, which does not contain the vulnerability.
The following patch releases address this vulnerability:
- SAP Commerce Cloud Patch Release 2105.4
- SAP Commerce Cloud Patch Release 2011.14
- SAP Commerce Cloud Patch Release 2005.19
- SAP Commerce Cloud Patch Release 1905.35
The Software Downloads of these or later patches are available in the SAP Support Portal. For information about installing patches, see About Patch Releases.
Workaround
To minimize the impact, restrictions to product related field length could be implemented to limit the size of inputs sent to jsoup. See Creating Validation Constraints in Backoffice.
Please assess the workaround applicability for your SAP landscape prior to implementation.
Note that this workaround is a temporary fix and is not a permanent solution. SAP strongly recommends you apply the corrections outlined in the security note, which can be done in lieu of the workaround or after the workaround is implemented.
Available fix and Supported packages
HY_COM|2005|2005|
HY_COM|2105|2105|
HY_COM|2011|2011|
SAP_APPL
CVSS
Score:7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploit
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/3113593
TAGS
DoS, DDoS, Distributed Denial of Service, Uncontrolled Resource consumption, Resource Exhaustion, CVE-2021-37714