High priority
SAP security note 2256185, “Potential Denial of Service in SAP Internet Communication Manager”, is a note released on March 14, 2016. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can remotely exploit SAP Internet Communication Manager, rendering it, and potentially the resources that are used to serve SAP Internet Communication Manager, unavailable.
Solution
To mitigate this vulnerability, please implement the Patch Level mentioned in this SAP Note. Applying the appropriate patch will address the resource exhaustion issue and restore the stability of the SAP Internet Communication Manager.
Reason and prerequisites
The issue is caused by a resource exhaustion condition. An attacker can send a specifically crafted request that causes the SAP Internet Communication Manager process to consume excessive resources. This prevents other processes from allocating necessary resources, effectively rendering the system unavailable and causing a denial of service.
CVSS
Score 7.5 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Full note on SAP: SAP Support Launchpad note 2256185
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
