Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential denial of service in BI-BIP, SAP security note 2067570

SAP Note 2067570
High priority

SAP security note 2067570, “Potential Denial of Service in BI-BIP”, was released on December 8, 2015. Below are the symptom and SAP recommended solution.

ComponentBusiness Intelligence Platform > BI Servers, Security, Crystal Reports in Launchpad
PriorityCorrection with high priority
StatusReleased for Customer
Released onDecember 8, 2015

Description

Symptom

An attacker can remotely exploit BI-BIP-SRV, rendering it, and potentially the resources that are used to serve BI-BIP, unavailable.

Solution

The issue has been fixed in the following support package patches:

Reason and prerequisites

An attacker can trigger functionality that causes the BI server processes to stop running, thereby launching a denial-of-service (DoS) attack.

CVSS

Score 7.1 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C

Full note on SAP: SAP Support Launchpad note 2067570

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More