Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential denial of service in SAP Sybase ASE, SAP security note 1893561

SAP Note 1893561

SAP security note 1893561, “Potential denial of service in SAP Sybase ASE”, is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

An attacker can launch a specifically crafted request causing the SAP Sybase ASE process on Microsoft Windows to be terminated. This results in SAP Sybase ASE becoming unavailable until the process is manually rebooted. This condition can be intentionally provoked by an attacker to cause a denial of service (DoS).

Solution

This issue has been fixed in the following SAP Sybase ASE versions on Microsoft Windows:

  • SAP Sybase ASE 15.7 SP100
  • SAP Sybase ASE 15.7 ESD#4

Install the fixed SAP Sybase ASE versions most appropriate for your production environments.

CVSS

Score 6.3 Vector: AV:N/AC:M/AU:S/C:N/I:N/A:C

Full note on SAP: SAP Support Launchpad note 1893561

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More