SAP security note 2657670, "[CVE-2018-2473] Denial of Service in Web Intelligence Richclient 3 Tiers Mode". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP BusinessObjects BI Platform Server using Web Intelligence Richclient 3 tiers mode gateway allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
Solution
A fix has been provided to prevent the Application Server from entering an infinite loop by blocking malformed inputs. This issue is fixed in the patches listed in the Support Package Patches section, see the BI 4.x Maintenance Strategy & Schedule.
Reason and prerequisites
The 3 tiers gateway is vulnerable to Denial of Service if a specially crafted HTTP request is sent to it.
CVSS
Score 7.7/10 Vector: AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
References
Affected components
- ENTERPRISE (410 to 420)
Full note on SAP: SAP Support Launchpad note 2657670
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




