SAP security note 1569300, "Potential Denial of Service in translation tools functionality", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Security Note 1569300 addresses a critical vulnerability that could allow a malicious user to perform a Denial of Service (DoS) attack on the translation tools functionality within SAP systems.
A malicious user can remotely exploit the translation tool functionality, rendering it unavailable. This exploitation can also affect the resources used to serve the translation tool functionality, potentially leading to system-wide unavailability.
Solution
To mitigate this vulnerability, implement the changes outlined in the correction instructions provided in the SAP Note. The solution involves disabling obsolete code, and no further testing is required after implementation.
Reason and prerequisites
The issue stems from a resource exhaustion condition. An attacker can send a specially crafted request that causes the process to consume excessive resources. This prevents other processes from allocating new resources, effectively making the system unavailable. The attacker can intentionally provoke this condition to cause a DoS.
References
This note refers to
Referenced by
Affected components
- SAP_BASIS: From 711 to 730
- SAP_BASIS: From 72L to 800
Full note on SAP: SAP Support Launchpad note 1569300
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
