Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Memory Corruption vulnerability in SAP NetWeaver Instance Agent Service, SAP security note 2509284

SAP Note 2509284SAP Security NoteMedium priority

SAP security note 2509284, "Memory Corruption Vulnerability in SAP NetWeaver Instance Agent Service", is a program error note released on 10.10.2017. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Client/Server Technology > Startup Service
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released on10.10.2017
LanguageEnglish

Description

Symptom

SAP startservice allows an attacker to leverage logical errors in memory management to cause a memory corruption. Some well-known impacts of this Memory Corruption vulnerability include:

  • System information disclosure or system crash in worst cases
  • Vulnerability might have a direct impact on the confidentiality, integrity, and availability of a system
  • Information gathered can be used to craft further attacks, possibly with more severe consequences

Solution

The kernel patch mentioned in this SAP Note includes the gSOAP patches to fix this problem.

Action Required: Install at least the kernel patch level mentioned in this SAP Note.

Reason and prerequisites

Only kernel versions 7.52 and 7.53 contain the problem! The software product uses the gSOAP library with a vulnerability described in the Genivia Security advisory: CVE-2017-9765, a bug in certain versions of gSOAP 2.7 up to 2.8.47 (June 21, 2017).

CVSS

Score 6.6 Vector: AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Affected components

  • KRNL64UC: 7.53
  • KERNEL: 7.52, 7.53

Full note on SAP: SAP Support Launchpad note 2509284

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More