Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Bufferoverflow in ABAP VM, SAP security note 2018221

SAP Note 2018221
High priority

SAP security note 2018221, "Buffer Overflow in ABAP VM", is a note released on August 12, 2014. Below are the symptom and SAP recommended solution.

ComponentBasis Components > ABAP Runtime Environment – ABAP Language Issues Only > Dynpro and CUA engine (BC-ABA-SC)
PriorityCorrection with high priority
StatusReleased for Customer
Released onAugust 12, 2014

Description

Symptom

The ABAP VM has a buffer overflow.

Solution

Please apply the patch level of the kernel (disp+work) mentioned in this SAP Note. Note that kernel 7.20 is the DCK for all earlier 7.x kernels.

Reason and prerequisites

A buffer overflow vulnerability exists in ABAP VM. This enables an attacker with developer permission to inject code or value into the working memory, making the work process unavailable.

CVSS

Score 6.3 Vector: AV:N/AC:M/AU:S/C:N/I:N/A:C

Full note on SAP: SAP Support Launchpad note 2018221

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More