SAP Security Note
High priority
SAP security note 2313631, "Denial of Service (DOS) in BILaunchPad and Central Management Console", is a program error note released on 13.06.2017. Below are the symptom and SAP recommended solution.
Description
Symptom
BI LaunchPad and Central Management Console allow an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
Some well-known impacts of Denial of Service vulnerability are:
- Long response delays and service interruptions, degrading service quality for legitimate users
- Direct impact on availability
Solution
This issue is fixed in the patches listed in the "Support Package Patches" section below.
The "Support Package Patches" section will be populated with the relevant patch levels once they are released.
For Business Intelligence Platform maintenance schedule and strategy, see the Knowledge Base Article 2144559 in the References section.
CVSS
Score 7.5 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References
This note refers to
- 2144559 – BI 4.x Maintenance Strategy & Schedule
Full note on SAP: SAP Support Launchpad note 2313631
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
