SAP Security Note
Medium priority
SAP security note 2290548, "Denial of service (DOS) vulnerability in BI Launchpad", was released on September 12, 2016. Below are the symptom, SAP recommended solution and references.
Description
Symptom
Infoview allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
Impacts of Denial of Service vulnerability:
- Long response delays and service interruptions, degrading the service quality experienced by legitimate users
- Direct impact on availability
Solution
This issue is fixed in the patches listed in the "Support Packages & Patches" section below.
For Business Intelligence Platform maintenance schedule and strategy, see the Knowledge Base Article 2144559.
CVSS
Score 6.5 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
References
- SAP Note 2144559 – BI 4.x Maintenance Strategy & Schedule
- SAP Note 2315665 – File Types supported for upload Local document in BI Launchpad and Central Management Console
Full note on SAP: SAP Support Launchpad note 2290548
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
