SAP security note 2597913, "[CVE-2018-2433] Denial of Service (DoS) in SAP Gateway". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Gateway has two similar Denial of Service (DoS) vulnerabilities that allow an attacker to prevent legitimate users from accessing a service by crashing or flooding the service. This can result in:
- Service Interruptions: Long response delays and degraded service quality for legitimate users
- Availability Impact: Direct reduction in system availability
Solution
This correction introduces a length check for data received from the network. To address these vulnerabilities, please apply the relevant version and patch level of SAP Gateway as specified in this SAP Note.
Reason and prerequisites
The vulnerabilities arise because SAP Gateway does not check the length of data received from the network, leading to potential resource exhaustion.
CVSS
Score 5.9 Vector: AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
References
Affected components
- SAP KERNEL 7.21 64-BIT UNICODE
- SAP KERNEL 7.22 64-BIT
- SAP KERNEL 7.49 64-BIT
- SAP KERNEL 7.53 64-BIT UNICODE
Full note on SAP: SAP Support Launchpad note 2597913
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



