Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Denial of service (DOS) in ABAP System’s Dispatcher, SAP security note 2552295

SAP Note 2552295
Medium priority

SAP security note 2552295, "Denial of service (DOS) in ABAP System’s Dispatcher", released on 12.12.2017. Below are the symptom, SAP recommended solution and the affected software components.

PriorityCorrection with medium priority
StatusReleased for Customer
Released on12.12.2017

Description

Symptom

The ABAP Dispatcher allows an internal attacker to prevent legitimate users from accessing a service by either crashing or flooding the service.

Impacts of Denial of Service vulnerability include:

  • Long response delays and service interruptions, degrading service quality for legitimate users
  • Direct impact on availability

Solution

  • Implement the correction provided in this SAP Note to ensure that special OK-codes are handled properly, preventing DOS situations.
  • Action Required: Apply the kernel patch level mentioned in this SAP Note.

Reason and prerequisites

SAP VMC must be disabled by setting the profile parameter vmcj/enable to false. The malicious user must enter a specific OK-code related to internal session OK-codes in the OK-code field.

Affected components

  • SAP KERNEL 7.45 64-BIT UNICODE
  • SAP KERNEL 7.45 64-BIT
  • SAP KERNEL 7.49 64-BIT UNICODE
  • SAP KERNEL 7.49 64-BIT
  • SAP KERNEL 7.53 64-BIT UNICODE
  • SAP KERNEL 7.53 64-BIT

Full note on SAP: SAP Support Launchpad note 2552295

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More