Medium priority
SAP security note 2552295, "Denial of service (DOS) in ABAP System’s Dispatcher", released on 12.12.2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The ABAP Dispatcher allows an internal attacker to prevent legitimate users from accessing a service by either crashing or flooding the service.
Impacts of Denial of Service vulnerability include:
- Long response delays and service interruptions, degrading service quality for legitimate users
- Direct impact on availability
Solution
- Implement the correction provided in this SAP Note to ensure that special OK-codes are handled properly, preventing DOS situations.
- Action Required: Apply the kernel patch level mentioned in this SAP Note.
Reason and prerequisites
SAP VMC must be disabled by setting the profile parameter vmcj/enable to false. The malicious user must enter a specific OK-code related to internal session OK-codes in the OK-code field.
Affected components
- SAP KERNEL 7.45 64-BIT UNICODE
- SAP KERNEL 7.45 64-BIT
- SAP KERNEL 7.49 64-BIT UNICODE
- SAP KERNEL 7.49 64-BIT
- SAP KERNEL 7.53 64-BIT UNICODE
- SAP KERNEL 7.53 64-BIT
Full note on SAP: SAP Support Launchpad note 2552295
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
