SAP security note 2509284, "Memory Corruption Vulnerability in SAP NetWeaver Instance Agent Service", is a program error note released on 10.10.2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP startservice allows an attacker to leverage logical errors in memory management to cause a memory corruption. Some well-known impacts of this Memory Corruption vulnerability include:
- System information disclosure or system crash in worst cases
- Vulnerability might have a direct impact on the confidentiality, integrity, and availability of a system
- Information gathered can be used to craft further attacks, possibly with more severe consequences
Solution
The kernel patch mentioned in this SAP Note includes the gSOAP patches to fix this problem.
Action Required: Install at least the kernel patch level mentioned in this SAP Note.
Reason and prerequisites
Only kernel versions 7.52 and 7.53 contain the problem! The software product uses the gSOAP library with a vulnerability described in the Genivia Security advisory: CVE-2017-9765, a bug in certain versions of gSOAP 2.7 up to 2.8.47 (June 21, 2017).
CVSS
Score 6.6 Vector: AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected components
- KRNL64UC: 7.53
- KERNEL: 7.52, 7.53
Full note on SAP: SAP Support Launchpad note 2509284
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
