SAP Security Note
High priority
SAP security note 2259547, “Potential denial of service in jstart”, is a note released on 14.03.2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can remotely exploit jstart, rendering it, and potentially the resources that are used to serve jstart, unavailable.
Solution
Apply the patch specified in this SAP Note 2259547.
By applying this patch, the "NetWeaver Administrator Heap Dump Analysis" will be affected. For details and the solution, refer to SAP Note 2283299.
Reason and prerequisites
The problem is caused by a resource exhaustion condition. An attacker can launch a specifically crafted request that causes the process to consume excessive resources. As a result, no other processes can allocate new resources, rendering the system unavailable. This condition can be intentionally provoked by an attacker to cause a denial of service.
CVSS
Score 7.5 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected components
- SAP KERNEL 7.21 to 7.47 (various versions)
Full note on SAP: SAP Support Launchpad note 2259547
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
