Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential denial of service in LOD-ESO-AS, SAP security note 1661747

SAP Note 1661747

SAP security note 1661747, "Potential denial of service in LOD-ESO-AS". Below are the symptom and SAP recommended solution.

Description

Symptom

An attacker can remotely exploit LOD-ESO-AS, rendering it and the resources that are used to service LOD-ESO-AS unavailable.

Solution

Fixes have been developed and released in version 5.0 J, Version 5.1 Patch 10, and all Version 7.0 SP and patch releases. Update to the appropriate Release/Patch version to mitigate this risk.

Reason and prerequisites

The problem is caused by a resource exhaustion condition. An attacker can launch a specifically crafted request that causes the process to consume excessive resources. As a result, no other processes can allocate new resources, rendering the system unavailable. This condition can be intentionally provoked by an attacker to cause a denial of service.

Full note on SAP: SAP Support Launchpad note 1661747

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More