SAP security note 2531656, "[CVE-2017-16683] Denial of service (DOS) in SAP BusinessObjects Platform". Below are the symptom and SAP recommended solution.
Description
Symptom
SAP BusinessObjects Platform allows an attacker to prevent legitimate users from accessing a service. A specially crafted request can make the Central Management Server crash. It will prevent legitimate users from accessing the system.
Some well-known impacts of Denial of Service vulnerability are:
- Long response delays and service interruptions, thus degrading the service quality experienced by legitimate users
- Direct impact on availability
Solution
This issue is fixed in the patches listed in the "Support Packages & Patches" section below.
The "Support Packages & Patches" section will be populated with the relevant patch levels once they are released.
For Business Intelligence Platform maintenance schedule and strategy see the Knowledge Base Article 2144559.
Reason and prerequisites
The Central Management Server does not properly handle some input values.
CVSS
Score 6.5 / 10 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Full note on SAP: SAP Support Launchpad note 2531656
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




