Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Aktualisierung 1 zu Sicherheitshinweis 1687910, SAP security note 1658025

SAP Note 1658025

SAP security note 1658025, "Update 1 to Security Note 1687910". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

Security note 1687910 was re-released due to missing validity entries. Newly added affected releases are listed below: Release 6.40.

Security note 1687910 has been re-released due to missing entries for support package patch levels. Newly added entries for SP patch levels are listed below: see list of kernel patch levels in this note.

Security note 1687910 has been re-released with updated CVSS information.

An attacker can remotely target the DIAG Processor to prevent the DIAG Processor from being available and possibly its required resources.

Solution

Please install an SAP kernel (disp+work) with at least one of the patch levels specified in this SAP Note. For information about installing the downward-compatible kernel 7.20, see SAP Note 1636252.

Reason and prerequisites

The validity of security note 1687910 has been enhanced with further affected releases.

Entries for support package patch levels are missing in security note 1687910.

The CVSS information from security note 1687910 has been added.

CVSS

Score 0

References

Affected components

  • KRNL32NUC: 6.40 to 6.40EX2
  • KRNL32NUC: 7.00 to 7.01
  • KRNL32NUC: 7.10 to 7.20
  • KRNL32NUC: 7.20EXT to 7.20EXT
  • KRNL32NUC: 7.21 to 7.21
  • Additional software component versions are listed in the full SAP Note

Full note on SAP: SAP Support Launchpad note 1658025

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More