Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0274 Denial of service (DOS) in SAP Work and Inventory Manager, SAP security note 2753497

SAP Note 2753497

SAP security note 2753497, "[CVE-2019-0274] Denial of service (DOS) in SAP Work and Inventory Manager". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Work Manager and SAP Inventory Manager allow an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

Some well-known impacts of Denial of Service vulnerability are:

  • Long response delays and service interruptions, thus degrading the service quality experienced by legitimate users
  • Direct impact on availability

Solution

The denial of service vulnerability is mitigated by correctly validating input data. To resolve this issue, upgrade to SMP Mobile Platform SDK 3.1 SP03 PL02, SDK 3.1 SP04, or later.

Reason and prerequisites

Both the SAP Work Manager client and the SAP Inventory Manager client are built using the SAP Mobile Platform SDK. The SAP Mobile Platform SDK Agentry Client is vulnerable to a denial of service attack on the Android platform. The other supported client platforms, iOS and Windows desktops, are not affected.

The vulnerability exists in both SAP Mobile Platform (SMP) SDK 3.0 and 3.1. Since SMP 3.0 is out of maintenance, customers are required to upgrade to SMP 3.1 or later to resolve the issue.

CVSS

Score 5.5 Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected components

  • AGENTRY_SDK 7.0
  • AGENTRY_SDK 7.1

Full note on SAP: SAP Support Launchpad note 2753497

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More