SAP security note 2389181, "Denial of Service Vulnerability in SAP NetWeaver Instance Agent Service", is released on 13 June 2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The Instance Agent Service (sapstartsrv) in SAP NetWeaver is vulnerable to Denial of Service (DoS) attacks. An attacker can prevent legitimate users from accessing the service by either crashing or flooding it with requests.
Solution
Apply at least the Kernel patch mentioned in this SAP Note. The Instance Agent Service (sapstartsrv) and SAP Host Agent in SAP HANA have been updated with the following revisions:
- SAP HANA1.00 SPS12: Revision 122.08
- SAP HANA2.0 SPS00: Revision 2.01
- SAP HANA2.0 SPS01: Revision 10
Ensure you update to these or later versions to mitigate the vulnerability.
CVSS
Score 7.5 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected components
- SAP NetWeaver Instance Agent Service (sapstartsrv)
- SAP Host Agent in SAP HANA
Full note on SAP: SAP Support Launchpad note 2389181
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
