Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2017-16683 Denial of service (DOS) in SAP BusinessObjects Platform, SAP security note 2531656

SAP Note 2531656

SAP security note 2531656, "[CVE-2017-16683] Denial of service (DOS) in SAP BusinessObjects Platform". Below are the symptom and SAP recommended solution.

Description

Symptom

SAP BusinessObjects Platform allows an attacker to prevent legitimate users from accessing a service. A specially crafted request can make the Central Management Server crash. It will prevent legitimate users from accessing the system.

Some well-known impacts of Denial of Service vulnerability are:

  • Long response delays and service interruptions, thus degrading the service quality experienced by legitimate users
  • Direct impact on availability

Solution

This issue is fixed in the patches listed in the "Support Packages & Patches" section below.

The "Support Packages & Patches" section will be populated with the relevant patch levels once they are released.

For Business Intelligence Platform maintenance schedule and strategy see the Knowledge Base Article 2144559.

Reason and prerequisites

The Central Management Server does not properly handle some input values.

CVSS

Score 6.5 / 10 Vector: AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Full note on SAP: SAP Support Launchpad note 2531656

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More