SAP Security Note
Medium priority
SAP security note 1541716, “Potential Denial of Service in translation tools functionality”, released on 17.01.2017. Below are the symptom and SAP recommended solution.
Description
Symptom
A malicious user can remotely exploit translation tool functionality, rendering it unavailable as well as potentially affecting the resources used to serve the translation tool functionality.
This security note has been updated. For more detailed information, see Security Note 1769099.
Solution
To resolve the issue, implement the changes contained in the attached correction instructions in your system.
Updated due to support package validity adjustment.
Reason and prerequisites
The problem is caused by a resource exhaustion condition. An attacker can launch a specifically crafted request, resulting in the process consuming excessive resources. Consequently, no other processes can allocate new resources, rendering the system unavailable. This condition can be intentionally provoked by an adversary to cause a Denial of Service.
References
Full note on SAP: SAP Support Launchpad note 1541716
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
