Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential denial of service in Message Server, SAP security note 2223688

SAP Note 2223688
SAP Security Note
Low priority

SAP security note 2223688, “Potential Denial of Service in Message Server”, is a program error note released on 08.03.2016. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBC-CST-MS (Basis Components > Client/Server Technology > Message Service)
CategoryProgram error
PriorityCorrection with low priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on08.03.2016
LanguageEnglish

Description

Symptom

An attacker can remotely exploit the message server, rendering it, and potentially the resources that are used to serve Message Server, unavailable.

Solution

Use the kernel mentioned in this SAP Note.

Reason and prerequisites

The problem is caused by a resource exhaustion condition. An attacker can launch a specifically crafted request that causes the process to consume excessive resources. As a result, no other processes can allocate new resources, rendering the system unavailable. This condition can be intentionally provoked by an attacker to cause a denial of service.

Affected components

  • KRNL32NUC: 7.21, 7.21EXT
  • KRNL32UC: 7.21, 7.21EXT
  • KRNL64NUC: 7.21, 7.21EXT, 7.42, 7.22, 7.22EXT
  • KRNL64UC: 7.21, 7.21EXT, 7.42, 7.22, 7.22EXT
  • KERNEL: 7.21 to 7.22, 7.42, 7.45

Full note on SAP: SAP Support Launchpad note 2223688

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More