Description
UPDATE 24th September 2019: This note has been re-released with updated ‘Reason and Prerequisites’ information.
SAP Kernel (RFC), SAP GUI for Windows and SAP GUI for Java allow an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. Some well-known impacts of Denial of Service vulnerability are –
- long response delays and service interruptions, thus degrading the service quality experienced by legitimate users
- direct impact on availability
Available fix and Supported packages
- KRNL32NUC | 7.21 | 7.21
- KRNL32NUC | 7.21EXT | 7.21EXT
- KRNL32UC | 7.21 | 7.21
- KRNL32UC | 7.21EXT | 7.21EXT
- KRNL64NUC | 7.21 | 7.21
- KRNL64NUC | 7.21EXT | 7.21EXT
- KRNL64NUC | 7.22 | 7.22
- KRNL64NUC | 7.22EXT | 7.22EXT
- KRNL64NUC | 7.49 | 7.49
- KRNL64UC | 7.21 | 7.21
- KRNL64UC | 7.21EXT | 7.21EXT
- KRNL64UC | 7.22 | 7.22
- KRNL64UC | 7.22EXT | 7.22EXT
- KRNL64UC | 7.49 | 7.49
- KRNL64UC | 7.53 | 7.53
- KRNL64UC | 7.73 | 7.73
- BC-FES-GUI | 7.50 | 7.50
- BC-FES-GUI | 7.60 | 7.60
- BC-FES-JAV | 7.50 | 7.50
- KERNEL | 7.21 | 7.22
- SAP GUI FOR JAVA 7.50 | SP007 | 000000
- SAP GUI FOR WINDOWS 7.50 CORE | SP011 | 000001
- SAP GUI FOR WINDOWS 7.60 CORE | SP002 | 000000
- SAP KERNEL 7.21 32-BIT | SP1310 | 001310
- SAP KERNEL 7.21 32-BIT UNICODE | SP1310 | 001310
- SAP KERNEL 7.21 64-BIT | SP1310 | 001310
- SAP KERNEL 7.21 64-BIT UNICODE | SP1310 | 001310
- SAP KERNEL 7.21 EXT 64-BIT | SP1310 | 001310
- SAP KERNEL 7.21 EXT 64-BIT UC | SP1310 | 001310
- SAP KERNEL 7.22 64-BIT | SP815 | 000815
- SAP KERNEL 7.22 64-BIT UNICODE | SP815 | 000815
- SAP KERNEL 7.22 EXT 64-BIT | SP815 | 000815
- SAP KERNEL 7.22 EXT 64-BIT UC | SP815 | 000815
- SAP KERNEL 7.49 64-BIT | SP715 | 000715
- SAP KERNEL 7.49 64-BIT UNICODE | SP715 | 000715
- SAP KERNEL 7.53 64-BIT | SP401 | 000401
- SAP KERNEL 7.53 64-BIT | SP422 | 000422
- SAP KERNEL 7.53 64-BIT UNICODE | SP401 | 000401
- SAP KERNEL 7.53 64-BIT UNICODE | SP422 | 000422
- SAP KERNEL 7.73 64-BIT UNICODE | SP210 | 000210
- SAP KERNEL 7.76 64-BIT UNICODE | SP016 | 000016
Affected component
- BC-MID-RFC
RFC
CVSS
Score: 5.3
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/2786151