Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Denial of service (DOS) vulnerability in HANA DP Agent, SAP security note 2262710

SAP Note 2262710

SAP security note 2262710, "Denial of service (DOS) vulnerability in HANA DP Agent". Below are the symptom and SAP recommended solution.

Description

Symptom

HANA DP Agent allows an attacker to prevent legitimate users from accessing a service by crashing or flooding the service. Impacts include:

  • Long response delays and service interruptions, degrading service quality for legitimate users.
  • Direct impact on availability.

Solution

SAP has provided a fix that validates the packet length in the communication before allocating memory in the DP Agent. To mitigate this vulnerability, upgrade HANA SDI DP Agent to:

  • 1.0 SP2
  • 1.0 SP1 Patch 3

Reason and prerequisites

This vulnerability exists in setups using HANA Smart Data Integration (SDI) with HANA DP Agent 1.0 SP1 Patch 2 or prior versions. An attacker can exploit this flaw by triggering a condition that causes the process to enter an endless loop, consuming all available processing time. This results in the entire machine becoming unresponsive until the process is manually terminated, enabling a denial-of-service (DoS) attack.

CVSS

Score 7.5 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Full note on SAP: SAP Support Launchpad note 2262710

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More