SAP security note 2125623, "Potential remote termination of running processes in BC-CCM-SLD-REG", is a program error note released on August 11, 2015. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can exploit BC-CCM-SLD-REG and potentially terminate it.
The issue is caused by a memory corruption that causes the process to terminate. An attacker can provoke a condition in which the process attempts to read outside its memory space, causing a memory protection fault. As a result, the system terminates the process, rendering the application unusable until it is restarted manually.
Solution
Apply the corresponding patch. You can download it here or view the PDF Version.
CVSS
Score 1.5 / 10 Vector: AV:L/AC:M/PR:S/UI:N/S:U/C:N/I:N/A:P
Affected components
- KRNL32NUC: Versions 7.20, 7.20EXT, 7.21, 7.21EXT
- KRNL32UC: Versions 7.20, 7.20EXT, 7.21, 7.21EXT
- KRNL64NUC: Versions 7.20, 7.20EXT, 7.21, 7.21EXT, 7.41, 7.42, 7.43, 7.22, 7.22EXT
- KRNL64UC: Versions 7.20, 7.20EXT, 7.21, 7.21EXT, 7.41, 7.42, 7.43, 7.22, 7.22EXT
- KERNEL: Versions 7.20 to 7.43
Full note on SAP: SAP Support Launchpad note 2125623
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
