Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

Denial of service (DOS) in SAP Commerce, SAP security note 3113593

Description

Symptom

The library jsoup used in SAP Commerce may be vulnerable to DOS attacks. jsoup is used to sanitize various product related metadata in b2caccelerator. A user with write access to product metadata could exploit this vulnerability.

The impacts of the vulnerability are –

  • Long response delays and service interruptions, thus degrading the service quality experienced by legitimate users
  • Direct impact on availability                         

Other Terms

DoSDDoS, Distributed Denial of Service, Uncontrolled Resource consumption, Resource Exhaustion, CVE-2021-37714

Reason and Prerequisites

This vulnerability affects any SAP Commerce installation using the B2C Accelerator.

Solution

SAP Commerce addresses this vulnerability by upgrading jsoup, which does not contain the vulnerability.

The following patch releases address this vulnerability:

The Software Downloads of these or later patches are available in the SAP Support Portal. For information about installing patches, see About Patch Releases.

Workaround

To minimize the impact, restrictions to product related field length could be implemented to limit the size of inputs sent to jsoup. See Creating Validation Constraints in Backoffice.

Please assess the workaround applicability for your SAP landscape prior to implementation.

Note that this workaround is a temporary fix and is not a permanent solution. SAP strongly recommends you apply the corrections outlined in the security note, which can be done in lieu of the workaround or after the workaround is implemented.

Available fix and Supported packages

HY_COM|1905|1905|
HY_COM|2005|2005|
HY_COM|2105|2105|
HY_COM|2011|2011|
 
Affected component

SAP_APPL

CVSS

Score:7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Exploit


Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/3113593

TAGS

DoS, DDoS, Distributed Denial of Service, Uncontrolled Resource consumption, Resource Exhaustion, CVE-2021-37714

More to explorer

RedRays at Black Hat MEA 2023

🔒 “FROM ON-PREMISES TO CLOUD: A COMPREHENSIVE ANALYSIS OF SAP SECURITY ISSUES” 🔒 📅 17:40, Wed, Nov 15📍 Briefing Stage 4 At

SAP Security For All

RedRays Security Platform for Penetration testers and Bug hunters

The product package is specifically created for cyber security experts who have encountered SAP while participating in bug bounty programs.

RedRays Security Platform for SAP Consultants

The product package is designed for SAP consultants conducting security assessments of SAP ERP systems. We provide essential tools and resources to help professionals in this field conduct their work effectively.

RedRays Security Platform for Enterprises

The product package is specifically optimized to cater to the needs of both small/medium and large companies who are seeking to streamline the process of organizing a comprehensive security system for ERP systems.