SAP security note 2313835, “Denial of service (DOS) in SAP Internet Communication Manager”, is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
SAP Internet Communication Manager allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
Impacts:
- Long response delays and service interruptions, degrading service quality for legitimate users
- Direct impact on availability
Solution
Apply the provided fix. SAP Internet Communication Manager will stop reading from the closed connection.
For more details, refer to SAP Note 1838675.
Reason and prerequisites
SAP Internet Communication Manager used in SAP Application Server Java is vulnerable to Denial of Service (DoS) if the P4 client does not send appropriate handshake data to the P4SEC port (P4 with SSL). The manager prints a warning to the trace file and closes the connection to the client. The crash occurs because it continues to read from the closed connection.
CVSS
Score 7.5 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Full note on SAP: SAP Support Launchpad note 2313835
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
