SAP Security Note
Medium priority
SAP security note 2430022, "Denial of service (DOS) in SAP Netweaver AS ABAP", is released on June 13, 2017. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can exploit this vulnerability by sending specially crafted requests to the application server, causing misbehavior such as crashes or flooding. This results in:
- Long response delays and service interruptions
- Direct impact on system availability
Solution
To mitigate this vulnerability:
- Upgrade the Kernel: Update to the kernel version that includes the fix. The specific kernel versions fixed are detailed in the note. For example, SAP KERNEL 7.49 64-BIT UNICODE: Support Package SP210; SAP KERNEL 7.45 64-BIT: Support Package SP414.
- Error Handling Improvements: The update enhances error handling to prevent deadlocks caused by malicious requests.
CVSS
Score 6.5
Full note on SAP: SAP Support Launchpad note 2430022
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
