High priority
SAP security note 2798243, "[CVE-2019-0350] Denial of service (DOS) in SAP HANA database", is a program error note released on August 13, 2019. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP HANA Database is susceptible to a Denial of Service (DoS) vulnerability that allows an attacker to prevent legitimate users from accessing the service by crashing the indexserver. This can lead to long response delays and service interruptions, directly impacting the availability of the SAP HANA database.
Impact:
- Service interruptions and degraded performance for legitimate users.
- Direct impact on the availability of the SAP HANA Database.
Solution
Apply the following revisions or later to mitigate the vulnerability:
- SAP HANA 1.00 SPS12: Revision 122.26
- SAP HANA 2.0 SPS02: Revision 24.10
- SAP HANA 2.0 SPS03: Revision 37.02
SAP HANA 2.0 SPS04 is not affected by this vulnerability.
Workaround: restrict network access to the SQL network port of the SAP HANA database to trusted users or applications to minimize the risk of exploitation.
CVSS
Score 7.5 Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected components
- SAP HANA Database 1.00
- SAP HANA Database 2.00
Full note on SAP: SAP Support Launchpad note 2798243
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
