Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential Denial of Service in translation tools funct., SAP security note 1541716

SAP Note 1541716
SAP Security Note
Medium priority

SAP security note 1541716, “Potential Denial of Service in translation tools functionality”, released on 17.01.2017. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Documentation and Translation Tools > Translation Tools
PriorityCorrection with medium priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on17.01.2017

Description

Symptom

A malicious user can remotely exploit translation tool functionality, rendering it unavailable as well as potentially affecting the resources used to serve the translation tool functionality.

This security note has been updated. For more detailed information, see Security Note 1769099.

Solution

To resolve the issue, implement the changes contained in the attached correction instructions in your system.

Updated due to support package validity adjustment.

Reason and prerequisites

The problem is caused by a resource exhaustion condition. An attacker can launch a specifically crafted request, resulting in the process consuming excessive resources. Consequently, no other processes can allocate new resources, rendering the system unavailable. This condition can be intentionally provoked by an adversary to cause a Denial of Service.

References

Full note on SAP: SAP Support Launchpad note 1541716

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More