Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2019-0314 Denial of service (DOS) in SAP Work Manager and SAP Inventory Manager, SAP security note 2793805

SAP Note 2793805
SAP Security Note
Medium priority

SAP security note 2793805, "[CVE-2019-0314] Denial of service (DOS) in SAP Work Manager and SAP Inventory Manager", is a program error note released on 11.06.2019. Below are the symptom and the SAP recommended solution.

ComponentBusiness Mobile > Syclo Mobility > Syclo Mobility for SAP backend > Syclo SAP Inventory Manager Application
CategoryProgram error
PriorityMedium priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on11.06.2019
LanguageEnglish

Description

Symptom

SAP Work Manager and SAP Inventory Manager allow an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

Some well-known impacts of Denial of Service vulnerability are:

  • Long response delays and service interruptions, thus degrading the service quality experienced by legitimate users
  • Direct impact on availability

Solution

The denial of service vulnerability is now prevented by correctly validating input data.

To resolve this issue, upgrade to:

  • SAP Work Manager 6.5 SP02 (client version 6.5.6) or later
  • SAP Inventory Manager 4.3 SP02 (client version 4.3.5) or later

Reason and prerequisites

The SAP Work Manager and Inventory Manager client is built using the SAP Mobile Platform SDK. The SAP Mobile Platform SDK Agentry Client is vulnerable to a denial of service attack on the Android platform. The other supported client platforms, iOS and Windows desktops, are not affected.

CVSS

Score 5.5 Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

References

  • CVE-2019-0314

Full note on SAP: SAP Support Launchpad note 2793805

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More