Description
After receiving a malicious HTTP request, the message server crashes with a memory violation.
Available fix and Supported packages
- KRNL32NUC | 6.40 | 6.40EX2
- KRNL32UC | 6.40 | 6.40EX2
- KRNL64NUC | 6.40 | 6.40EX2
- KRNL64UC | 6.40 | 6.40EX2
- SAP_BASIS | 700 | 701
- KERNEL | 6.40 | 6.40
- SAP KERNEL 7.01 32-BIT | SP073 | 000073
- SAP KERNEL 7.01 32-BIT UNICODE | SP073 | 000073
- SAP KERNEL 7.01 64-BIT | SP073 | 000073
- SAP KERNEL 7.01 64-BIT UNICODE | SP073 | 000073
Affected component
- BC-CST-MS
Message Service
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1414085