Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Denial of service (DOS) vulnerability in BPM, SAP security note 2296909

SAP Note 2296909

SAP security note 2296909, “Denial of service (DOS) vulnerability in BPM”, is a note released on 09.08.2016. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Business Management > Business Process Management (BPM) > Process Desk
Released on09.08.2016

Description

Symptom

The BPM component allows an attacker to prevent legitimate users from accessing a service by either crashing or flooding the service. This Denial of Service (DoS) vulnerability can lead to:

  • Long response delays and service interruptions, degrading service quality for legitimate users.
  • Direct impact on availability.

Solution

Resolving of external entities has been disabled during XML parsing. To correct this issue:

CVSS

Score 6.4 Vector: AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H

Full note on SAP: SAP Support Launchpad note 2296909

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More