Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Denial of service (DOS) in SAP NetWeaver Instance Agent Service, SAP security note 2389181

SAP Note 2389181

SAP security note 2389181, "Denial of Service Vulnerability in SAP NetWeaver Instance Agent Service", is released on 13 June 2017. Below are the symptom, SAP recommended solution and the affected software components.

StatusReleased for Customer
Released on13 June 2017

Description

Symptom

The Instance Agent Service (sapstartsrv) in SAP NetWeaver is vulnerable to Denial of Service (DoS) attacks. An attacker can prevent legitimate users from accessing the service by either crashing or flooding it with requests.

Solution

Apply at least the Kernel patch mentioned in this SAP Note. The Instance Agent Service (sapstartsrv) and SAP Host Agent in SAP HANA have been updated with the following revisions:

  • SAP HANA1.00 SPS12: Revision 122.08
  • SAP HANA2.0 SPS00: Revision 2.01
  • SAP HANA2.0 SPS01: Revision 10

Ensure you update to these or later versions to mitigate the vulnerability.

CVSS

Score 7.5 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected components

  • SAP NetWeaver Instance Agent Service (sapstartsrv)
  • SAP Host Agent in SAP HANA

Full note on SAP: SAP Support Launchpad note 2389181

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More