SAP security note 2674215, "Denial of service (DOS) in OPC UA applications of SAP Plant Connectivity". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This SAP Security Note addresses two critical vulnerabilities in SAP Plant Connectivity OPC UA applications that could lead to Denial of Service (DoS):
- CVE-2018-12585: an XML External Entity (XXE) vulnerability allows attackers to crash or flood the OPC UA server, preventing legitimate users from accessing services.
- CVE-2018-12086: a stack overflow vulnerability enables attackers to disrupt services by causing the OPC UA server to crash.
Solution
Apply the respective patch based on your SAP Plant Connectivity version.
- Backup: execute a data backup before starting the installation.
- Stop Services: ensure all agent instances are stopped and the Management Console is closed.
- Install Patch: download the appropriate installation program from the SAP Service Marketplace and follow the instructions in the installation guide.
- Restart System: if the installation program requests a system restart, perform it before continuing.
CVSS
Score 8.2/10
Score 7.5/10
References
- NIST NVD
Affected components
- SAP Plant Connectivity (15.0, 15.1, 15.2)
Full note on SAP: SAP Support Launchpad note 2674215
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



