Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2433 Denial of Service (DOS) in SAP Gateway, SAP security note 2597913

SAP Note 2597913

SAP security note 2597913, "[CVE-2018-2433] Denial of Service (DoS) in SAP Gateway". Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Gateway has two similar Denial of Service (DoS) vulnerabilities that allow an attacker to prevent legitimate users from accessing a service by crashing or flooding the service. This can result in:

  • Service Interruptions: Long response delays and degraded service quality for legitimate users
  • Availability Impact: Direct reduction in system availability

Solution

This correction introduces a length check for data received from the network. To address these vulnerabilities, please apply the relevant version and patch level of SAP Gateway as specified in this SAP Note.

Reason and prerequisites

The vulnerabilities arise because SAP Gateway does not check the length of data received from the network, leading to potential resource exhaustion.

CVSS

Score 5.9 Vector: AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

References

Affected components

  • SAP KERNEL 7.21 64-BIT UNICODE
  • SAP KERNEL 7.22 64-BIT
  • SAP KERNEL 7.49 64-BIT
  • SAP KERNEL 7.53 64-BIT UNICODE

Full note on SAP: SAP Support Launchpad note 2597913

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More