High priority
SAP security note 2405918, "Denial of Service (DoS) Vulnerability in SAP Netweaver Dynpro Engine", is a note released on March 14, 2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Netweaver Application Server ABAP’s Dynpro Engine has a vulnerability that allows an attacker to perform a Denial of Service (DoS) attack. This can lead to crashing or flooding the service, preventing legitimate users from accessing it. Impacts include long response delays, service interruptions, and direct availability issues.
Solution
SAP has released a patch to address this vulnerability. It is crucial to implement the specified patch level of the kernel as mentioned in SAP Note 2405918 to mitigate the risk.
CVSS
Score 7.5 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected components
- SAP KERNEL 32-BIT and 64-BIT UNICODE: 7.21, 7.21EXT, 7.22, 7.22EXT, 7.42, 7.49, 7.50, 7.51, 7.52
Full note on SAP: SAP Support Launchpad note 2405918
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
