SAP security note 2848498, "[CVE-2020-6304] Denial of Service (DoS) in SAP NetWeaver Internet Communication Manager". Below are the symptom and SAP recommended solution.
Description
Symptom
Internet Communication Manager (ICM) allows an attacker to prevent legitimate users from accessing ICM services by crashing the ICM process.
Solution
By applying the correction, the buffer overflow will be detected and programmatically managed. Please apply at least the patch level specified in the section “Support Packages & Patches”.
Reason and prerequisites
By sending a specially crafted packet to the IIOP or P4 service, an attacker can cause the ICM process to crash due to a buffer overflow. This is caused by a program error.
CVSS
Score 5.9 Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Full note on SAP: SAP Support Launchpad note 2848498
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
