SAP security note 2633366, "Denial of service (DOS) in iXML Toolset of SAP Kernel". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The iXML Toolset of SAP Kernel allows an attacker to prevent legitimate users from accessing a service by either crashing or flooding the service.
Impacts of the denial of service vulnerability:
- Long response delays and service interruptions, degrading the service quality for legitimate users.
- Direct impact on availability.
Solution
The handling of endless loops has been hardened. The correction is part of the SAP Kernel. With the correction installed, the iXML parser will raise the parse error: unexpected symbol: ‘#’.
Please install a SAP Kernel version with a patch level equal to or higher than listed in the Support Package Patches section.
Reason and prerequisites
This issue occurs only in SAP Kernel 7.53 used in ABAP Server 7.52.
References
Affected components
- KRNL64UC: From 7.53 to 7.53
- KERNEL: From 7.53 to 7.53
Full note on SAP: SAP Support Launchpad note 2633366
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
