SAP security note 2392719, "Potential Denial of Service vulnerability in Adobe Document Services". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Adobe Document Services uses an open source software version – Apache Santuario, for which security vulnerabilities were detected. These allow remote attackers to cause a denial of service (memory consumption) via crafted Document Type Definitions (DTDs), related to signatures.
Solution
Apply the corresponding ADS Support Package (SP) or respective patch.
Reason and prerequisites
This SAP Note is only applicable in case you use:
- ADS (Adobe Document Services) on NetWeaver 7.30, 7.31, 7.40, or 7.50.
CVSS
Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
References
Affected components
- ADSSAP 7.30
- ADSSAP 7.31
- ADSSAP 7.40
- ADSSAP 7.50
Full note on SAP: SAP Support Launchpad note 2392719
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



