SAP security note 1661747, "Potential denial of service in LOD-ESO-AS". Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can remotely exploit LOD-ESO-AS, rendering it and the resources that are used to service LOD-ESO-AS unavailable.
Solution
Fixes have been developed and released in version 5.0 J, Version 5.1 Patch 10, and all Version 7.0 SP and patch releases. Update to the appropriate Release/Patch version to mitigate this risk.
Reason and prerequisites
The problem is caused by a resource exhaustion condition. An attacker can launch a specifically crafted request that causes the process to consume excessive resources. As a result, no other processes can allocate new resources, rendering the system unavailable. This condition can be intentionally provoked by an attacker to cause a denial of service.
Full note on SAP: SAP Support Launchpad note 1661747
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



