Multiple vulnerabilities exist in SAP Web AS version 6.40 below patch 136 and 7.00 below patch 66. These flaws allow for remote file disclosure, remote denial of service attacks, and local privilege escalation.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/54328/sapwebas-dos.txt
Source: https://packetstormsecurity.com/files/54328/sapwebas-dos.txt.html