SAP security note 2445071, "Denial of service (DOS) in SAP NetWeaver Message Server". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP NetWeaver Message Server allows an attacker to prevent legitimate users from accessing a service by either crashing or flooding the service. This Denial of Service (DoS) vulnerability can lead to:
- Long response delays and service interruptions, degrading the service quality for legitimate users
- Direct impact on system availability
Solution
Apply at least the Kernel patch mentioned in this SAP Note. This patch addresses the vulnerability by preventing the SAP Message Server from being affected by these specially crafted administration messages.
Reason and prerequisites
An attacker can send specially crafted administration messages to the SAP Message Server, allowing them to change and reset the statistic level, leading to service disruption.
CVSS
Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Affected components
- SAP KERNEL 7.21 (32-bit/64-bit)
- SAP KERNEL 7.22 (32-bit/64-bit)
- SAP KERNEL 7.45 (32-bit/64-bit)
- SAP KERNEL 7.49 (32-bit/64-bit)
Full note on SAP: SAP Support Launchpad note 2445071
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
