High priority
SAP security note 2067570, “Potential Denial of Service in BI-BIP”, was released on December 8, 2015. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can remotely exploit BI-BIP-SRV, rendering it, and potentially the resources that are used to serve BI-BIP, unavailable.
Solution
The issue has been fixed in the following support package patches:
Reason and prerequisites
An attacker can trigger functionality that causes the BI server processes to stop running, thereby launching a denial-of-service (DoS) attack.
CVSS
Score 7.1 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:C
Full note on SAP: SAP Support Launchpad note 2067570
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




