Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3460407
was released on
11.06.2024 and deals with
"[CVE-2024-34688] Denial of service (DOS) in SAP NetWeaver AS Java (Meta Model Repository)" within Java.
We advice you to follow the instructions, to resolve
denial of service (dos)
with a
high potential for exploitation
in component BC-DWB-JAV-MMR.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as monthly patch process.
Denial of Service (DoS) attacks that take a system offline may lead to significant cost for the company, studies quantify the costs in average between 4 and 5 millions dollars. Business continuity requires SAP systems staying online. The CVSS scores or vulnerability descriptions are not enough to represent how a simple bug can lead to a significant loss for companies.
Risk specification
This note has been re-released with updated support packages & patches information. A vulnerability in the Meta Model Repository services in SAP NetWeaver AS Java allows an unauthenticated attacker to exhaust the system resources due to a missing authorization check, resulting in denial of service of the application.Solution
The issue has been resolved by adding an authorization check in the code.
Affected System
SAP Netweaver Application Server Java is part of the SAP NetWeaver Application Platform. It provides the complete infrastructure for deploying and running Java applications.
- The AS Java Home: SAP Netweaver Application Server Java wiki
- A dedicated SAP NetWeaver 7.40 Application Server for Java Security Guide exists.
The advisory is valid for
- MMR_SERVER 7.50
- 9.8 Multiple vulnerabilities associated with Reprise License Manager 14.2 component used with SAP 3D Visual Enterprise License Manager
- 7.8 [CVE-2023-33990] Denial of service (DOS) vulnerability in SAP SQL Anywhere
- 7.7 [CVE-2023-35871] Memory Corruption vulnerability in SAP Web Dispatcher
- 7.5 [CVE-2023-32111] Memory Corruption vulnerability in SAP PowerDesigner (Proxy)
- 7.5 [CVE-2020-6186] Denial of Service (DOS) Vulnerability in SAP Host Agent