Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6304 Denial of service (DOS) in SAP NetWeaver Internet Communication Manager, SAP security note 2848498

SAP Note 2848498

SAP security note 2848498, "[CVE-2020-6304] Denial of Service (DoS) in SAP NetWeaver Internet Communication Manager". Below are the symptom and SAP recommended solution.

Description

Symptom

Internet Communication Manager (ICM) allows an attacker to prevent legitimate users from accessing ICM services by crashing the ICM process.

Solution

By applying the correction, the buffer overflow will be detected and programmatically managed. Please apply at least the patch level specified in the section “Support Packages & Patches”.

Reason and prerequisites

By sending a specially crafted packet to the IIOP or P4 service, an attacker can cause the ICM process to crash due to a buffer overflow. This is caused by a program error.

CVSS

Score 5.9 Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Full note on SAP: SAP Support Launchpad note 2848498

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More