Skip links

Potential denial of service in Web Application Components, SAP security note 1677291

Description

An attacker can remotely exploit SAP Web Application Servers – through IC Manager, Web Dispatcher, or Message Server – rendering it, and potentially the resources that are used to serve SAP Web Application Servers, become unavailable.

Available fix and Supported packages

  • KRNL32NUC | 6.40 | 6.40EX2
  • KRNL32NUC | 7.00 | 7.01
  • KRNL32NUC | 7.10 | 7.20
  • KRNL32NUC | 7.20EXT | 7.20EXT
  • KRNL32NUC | 7.21 | 7.21
  • KRNL32NUC | 7.21EXT | 7.21EXT
  • KRNL32UC | 6.40 | 6.40EX2
  • KRNL32UC | 7.00 | 7.01
  • KRNL32UC | 7.10 | 7.20
  • KRNL32UC | 7.20EXT | 7.20EXT
  • KRNL32UC | 7.21 | 7.21
  • KRNL32UC | 7.21EXT | 7.21EXT
  • KRNL64NUC | 6.40 | 6.40EX2
  • KRNL64NUC | 7.00 | 7.01
  • KRNL64NUC | 7.10 | 7.20
  • KRNL64NUC | 7.20EXT | 7.20EXT
  • KRNL64NUC | 7.21 | 7.21
  • KRNL64NUC | 7.21EXT | 7.21EXT
  • KRNL64UC | 6.40 | 6.40EX2
  • KRNL64UC | 7.00 | 7.01
  • SAP KERNEL 6.40 32-BIT | SP405 | 000405
  • SAP KERNEL 6.40 32-BIT UNICODE | SP405 | 000405
  • SAP KERNEL 6.40 64-BIT | SP405 | 000405
  • SAP KERNEL 6.40 64-BIT UNICODE | SP405 | 000405
  • SAP KERNEL 6.40_EX2 32-BIT | SP405 | 000405
  • SAP KERNEL 6.40_EX2 32-BIT UC | SP405 | 000405
  • SAP KERNEL 6.40_EX2 64-BIT | SP405 | 000405
  • SAP KERNEL 6.40_EX2 64-BIT UC | SP405 | 000405
  • SAP KERNEL 7.00 32-BIT | SP344 | 000344
  • SAP KERNEL 7.00 32-BIT UNICODE | SP344 | 000344
  • SAP KERNEL 7.00 64-BIT | SP344 | 000344
  • SAP KERNEL 7.00 64-BIT UNICODE | SP344 | 000344
  • SAP KERNEL 7.01 32-BIT | SP188 | 000188
  • SAP KERNEL 7.01 32-BIT UNICODE | SP188 | 000188
  • SAP KERNEL 7.01 64-BIT | SP188 | 000188
  • SAP KERNEL 7.01 64-BIT UNICODE | SP188 | 000188
  • SAP KERNEL 7.10 32-BIT | SP273 | 000273
  • SAP KERNEL 7.10 32-BIT UNICODE | SP273 | 000273
  • SAP KERNEL 7.10 64-BIT | SP273 | 000273
  • SAP KERNEL 7.10 64-BIT UNICODE | SP273 | 000273

Affected component

    BC-CST
    Client/Server Technology

CVSS

Score: 0

Exploit

Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.

URL

https://launchpad.support.sap.com/#/notes/1677291

TAGS

#DoS
#denial-of-serviceIC-Manager
#Internet-Communication-Manager
#Web-DispatcherMessage-ServerDenial-of-Service-through-Hashtable-Collisions

How to detect over 4100 vulnerabilities in SAP Systems?

More to explorer

Initiating SAP Penetration Testing

►   Pentest, short for penetration testing, refers to a set of processes that simulate an attacker’s actions to identify security vulnerabilities. Companies

SAP Security Patch Day RedRays

May 2024 SAP Security Patch Day

Vulnerability: Multiple vulnerabilities in SAP CX Commerce SAP Component: CEC-SCC-PLA-PL CVE ID: CVE-2019-17495 CVSS Score: 9.8 CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Category: Program error