Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential denial of service in http provider of Web AS Java, SAP security note 1562064

SAP Note 1562064
SAP Security Note
HotNews

SAP security note 1562064, “Potential denial of service in http provider of Web AS Java”, is a note released on September 13, 2011. Below are the symptom, SAP recommended solution and references.

ComponentBasis Components > NetWeaver Application Server Java > Web Container, HTTP, JavaMail, Servlets
PriorityHotNews
TypeSAP Security Note
Version4
StatusReleased for Customer
Released onSeptember 13, 2011

Description

Symptom

A malicious user can remotely exploit the HTTP service on the dispatcher process of Web AS Java (J2EE), rendering it and potentially the resources used by the dispatcher process unavailable.

Solution

Update to the latest version of SAP Web AS (J2EE). If updating is not possible, apply one of the patches listed in the SP Patch Level section of the note.

Reason and prerequisites

The issue is caused by a resource exhaustion condition. An attacker can send a specifically crafted request that causes the process to consume excessive resources. Consequently, other processes cannot allocate new resources, rendering the system unavailable. This condition can be intentionally induced by an adversary to cause a Denial of Service.

References

Full note on SAP: SAP Support Launchpad note 1562064

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More