SAP security note 2090692, "Security vulnerability in ICM content filter [sapcsa]", is a note released on January 12, 2015. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can enlarge HTTP requests to a size where the content is not checked by the filter in ICM.
Solution
Perform an upgrade of your kernel. Use the kernel patches listed in this note.
Reason and prerequisites
The content filter does not check content that is larger than the internal memory buffer. The SAP profile parameter mpi/buffer_size defines the size of this buffer, which is set to 64 KB by default. If a request exceeds this size, the content is not checked.
CVSS
Score 6.0 Vector: AV:N/AC:M/PR:S/C:P/I:P/A:P
References
Full note on SAP: SAP Support Launchpad note 2090692
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
