SAP Security Note
High priority
SAP security note 2037492, “Potential denial of service in SAP Router”, is a program error note released on October 14, 2014. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can remotely exploit the SAProuter process to render it unavailable. This can potentially affect the resources used to serve SAProuter, leading to a denial of service.
Solution
Implement the latest kernel with the included patch. You can download the patch using the Download for SNOTE link or the PDF Version link.
Reason and prerequisites
The issue is caused by a resource exhaustion condition. An attacker can send a specifically crafted request that causes the process to consume excessive resources. This prevents other processes from allocating new resources, making the system unavailable. This condition can be intentionally triggered by an attacker to cause a denial of service.
CVSS
Score 7.1 Vector: AV:N/AC:M/AU:N/C:N/I:N/A:C
Affected components
- KRNL32NUC: 7.20, 7.20EXT, 7.21, 7.21EXT
- KRNL32UC: 7.20, 7.20EXT, 7.21, 7.21EXT
- KRNL64NUC: 7.20, 7.20EXT, 7.21, 7.21EXT, 7.40, 7.41, 7.42
- KRNL64UC: 7.20, 7.20EXT, 8.04, 7.21, 7.21EXT, 7.40, 7.41, 7.42
- KERNEL: 7.20 to 7.21, 8.04, 7.40, 7.41, 7.42
Full note on SAP: SAP Support Launchpad note 2037492
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
