Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Denial of service (DOS) vulnerability in Enqueue Server, SAP security note 2258784

SAP Note 2258784
SAP Security Note
High priority

SAP security note 2258784, "Denial of service (DOS) vulnerability in Enqueue Server", is a program error note released on April 12, 2016. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Client/Server Technology > Enqueue
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version5
StatusReleased for Customer
Released onApril 12, 2016

Description

Symptom

An attacker can prevent legitimate users from accessing the Enqueue service by either crashing or flooding it. This leads to:

  • Long response delays and service interruptions, degrading the service quality experienced by legitimate users.
  • Direct impact on system availability.

Solution

Implement the patch level mentioned in this SAP Note for Standalone Enqueue Server (ENSA). This correction ensures that internal variables of ENSA are properly initialized at start time, mitigating the DoS vulnerability.

CVSS

Score 7.5 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected components

  • SAP KERNEL 7.21
  • SAP KERNEL 7.22
  • SAP KERNEL 7.42
  • SAP KERNEL 7.45
  • SAP KERNEL 7.46
  • SAP KERNEL 7.47

Full note on SAP: SAP Support Launchpad note 2258784

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More