Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential remote termination and denial of service in IGS, SAP security note 2164133

SAP Note 2164133SAP Security NoteMedium priority

SAP security note 2164133, "Potential remote termination and denial of service in IGS", is a program error note released on 13.10.2015. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Frontend Services (SAP Note 1322184) > Internet Graphics Server
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version2
StatusReleased for Customer
Released on13.10.2015
LanguageEnglish

Description

Symptom

  • An attacker can remotely exploit IGS to manually terminate it.
  • Exploiting IGS can render it and its associated resources unavailable.
  • Full control of the product can be achieved by an attacker, including viewing, changing, or deleting data.

Solution

Download and install the IGS patch level 10 or higher.

Reason and prerequisites

  • Memory Corruption: Causes the process to terminate by provoking a condition where the process reads outside its memory space, leading to a memory protection fault.
  • Resource Exhaustion: Launching specially crafted requests can consume excessive resources, preventing other processes from allocating new resources and causing system unavailability.
  • Buffer Overflow: Allows attackers to inject and execute code within the application's working memory or cause the application to terminate.

Full note on SAP: SAP Support Launchpad note 2164133

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More

Three identical server cabinets carrying stacks of code of very different heights beside a measuring rule

ABAP Code Security Scan Cost Drivers

What moves the cost of an ABAP code security scan: custom object counts, effective lines, systems in scope, transport gating, triage and retest.