SAP security note 2480857, "Denial of Service in SAP NetWeaver Web Dynpro ABAP". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Web Dynpro ABAP allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
Some well-known impacts of a Denial of Service vulnerability include:
- Service Disruptions: Long response delays and service interruptions degrade the quality of service experienced by legitimate users.
- Availability Impact: Direct impact on the availability of the service.
Solution
The solution prevents creating dumps or x messages to reduce resource consumption. Please use the attached correction instructions or apply an appropriate service pack.
Reason and prerequisites
Cause: Error in source code.
CVSS
Score 5.3 / 10 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected components
- SAP_UI: Versions 740, 750, 751, 752
- SAP_BASIS: Versions 700 to 702, 710 to 711, 730 to 731, 769 to 770, 804
Full note on SAP: SAP Support Launchpad note 2480857
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
