Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential Denial of Service vulnerability in SAP Standalone Enqueue Server, SAP security note 2476937

SAP Note 2476937SAP Security NoteHigh priority

SAP security note 2476937, "Potential Denial of Service vulnerability in SAP Standalone Enqueue Server", is a program error note released on 10.10.2017. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Client/Server Technology > Enqueue
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version7
StatusReleased for Customer
Released on10.10.2017
LanguageEnglish

Description

Symptom

An attacker can remotely exploit the SAP Standalone Enqueue Server, rendering it unavailable and potentially making the resources used to serve the SAP Standalone Enqueue Server inaccessible.

Solution

SAP has addressed this vulnerability by improving the handling of parameters when accepting new connections. To apply the correction, ensure that you apply the ENSERVER package at least at the patch level mentioned in this SAP Note.

Reason and prerequisites

The issue arises from a resource exhaustion condition. An attacker can send a specifically crafted request that causes the process to consume excessive resources, leading to system unavailability.

CVSS

Score 7.5 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Full note on SAP: SAP Support Launchpad note 2476937

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More