Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential denial of service in ICM, SAP security note 1966655

SAP Note 1966655
High priority

SAP security note 1966655, “Potential denial of service in ICM”, is a note released on 26.10.2015. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Client/Server Technology
PriorityCorrection with high priority
StatusReleased for Customer
Released on26.10.2015

Description

Symptom

An attacker can remotely exploit the Internet Communication Manager (ICM), rendering it, and potentially the resources that are used to serve the ICM or application server, unavailable.

Solution

Apply the kernel patch level specified in this SAP Note and configure the ICM in accordance with SAP Note 1981955. Alternatively, you can also use an upstream SAP Web Dispatcher with a corresponding configuration to protect the system.

Reason and prerequisites

The problem is caused by a resource exhaustion condition. An attacker can launch a specifically crafted request that causes the process to consume excessive resources. As a result, no other processes can allocate new resources, rendering the system unavailable. This condition can be intentionally provoked by an attacker to cause a denial of service.

CVSS

Score 7.1 Vector: AV:N/AC:M/AU:N/C:N/I:N/A:C

Full note on SAP: SAP Support Launchpad note 1966655

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More