Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential denial of service in BI-BIP, SAP security note 2001106

SAP Note 2001106

SAP security note 2001106, “Potential denial of service in BI-BIP”, is a note. Below are the symptom and SAP recommended solution.

Description

Symptom

An attacker can remotely exploit BI-BIP, rendering it, and potentially the resources that are used to serve BI-BIP, unavailable.

Solution

Install one of the following or one of their subsequent patches or support packs:

  • BI 4.0 Patch 9.1
  • BI 4.0 SP10
  • BI 4.1 SP04

Reason and prerequisites

The problem is caused by an attacker sending a specifically crafted request to BI-BIP, causing servers to shut down.

CVSS

Score 7.1 Vector: AV:N/AC:M/AU:N/C:N/I:N/A:C

Full note on SAP: SAP Support Launchpad note 2001106

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More