SAP Security Note
High priority
SAP security note 2258784, "Denial of service (DOS) vulnerability in Enqueue Server", is a program error note released on April 12, 2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can prevent legitimate users from accessing the Enqueue service by either crashing or flooding it. This leads to:
- Long response delays and service interruptions, degrading the service quality experienced by legitimate users.
- Direct impact on system availability.
Solution
Implement the patch level mentioned in this SAP Note for Standalone Enqueue Server (ENSA). This correction ensures that internal variables of ENSA are properly initialized at start time, mitigating the DoS vulnerability.
CVSS
Score 7.5 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected components
- SAP KERNEL 7.21
- SAP KERNEL 7.22
- SAP KERNEL 7.42
- SAP KERNEL 7.45
- SAP KERNEL 7.46
- SAP KERNEL 7.47
Full note on SAP: SAP Support Launchpad note 2258784
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



