SAP security note 2366713, "Missing Input Length Validation in Runtime Workbench", is a program error note released on March 3, 2017. Below are the symptom and SAP recommended solution.
Description
Symptom
PI Runtime Workbench does not sufficiently validate the input length of parameters taken from an untrusted source. This vulnerability can lead to denial-of-service (DoS) conditions in successful exploits.
Solution
This vulnerability is fixed with the Support Packages and Patches referenced in this SAP Security Note. Please apply the appropriate patches for your environment.
CVSS
Score 6.5 Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
References
- SAP Note 2463577 – Collective note: SAP NETWEAVER 7.31 SP20 – Process Orchestration (PI)
- SAP Note 2417549 – Upgrade deployment fails caused by table XI_RWB_MSG
- SAP Note 2403195 – Corrections for unified rendering 701/19 III (UR Mimes)
Full note on SAP: SAP Support Launchpad note 2366713
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
