SAP security note 2121661, “Potential Remote Termination of Running Processes in ABAP & Java Server”, is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can remotely exploit various components of ABAP and Java Server, as well as RFC-bound external components, potentially terminating running processes. This issue is caused by a memory corruption that leads the process to attempt reading outside its memory space, resulting in a memory protection fault. Consequently, the system terminates the process, rendering the application unusable until it is manually restarted.
Solution
To mitigate this vulnerability, apply the following updates:
- SAP Kernel: Upgrade to a version equal to or higher than those specified in the Support Package Patches section.
- jstart: Use a version as described in the Kernel patches section.
- R3trans: Update to at least version 11.02.15 as per SAP Note 19466.
- R3load: Upgrade to the version mentioned in SAP Note 2136942 and download from SAP Note 1724496.
- SAP NetWeaver RFC SDK: Use at least version 7.21 PL 34 (SAP Note 1025361).
- SAP Java Connector (JCo): Upgrade to at least JCo 3.0.13 (SAP Note 2155739).
- SAP .NET Connector: Use version 3.0.15 or higher (SAP Note 2095394).
- ABAP Development Tools for SAP NetWeaver: Upgrade to at least version 2.41 (SAP Note 2126477).
- HANA Studio: Use at least HANA Studio 2.0.12, part of HDB 1.0 revision 94.
Ensure all relevant patches are applied to maintain system security and stability.
CVSS
Score 8.3 / 10 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:C
References
- SAP Note 2127995 – Potential remote termination of running processes in Content Server
- SAP Note 2125316 – Potential termination of running processes in SAPCAR
- SAP Note 2124806 – Potential remote termination of running processes in SAP GUI
Affected components
- BC-MID-RFC – Various versions from 7.20 to 8.04
Full note on SAP: SAP Support Launchpad note 2121661
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
