SAP security note 2001106, “Potential denial of service in BI-BIP”, is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can remotely exploit BI-BIP, rendering it, and potentially the resources that are used to serve BI-BIP, unavailable.
Solution
Install one of the following or one of their subsequent patches or support packs:
- BI 4.0 Patch 9.1
- BI 4.0 SP10
- BI 4.1 SP04
Reason and prerequisites
The problem is caused by an attacker sending a specifically crafted request to BI-BIP, causing servers to shut down.
CVSS
Score 7.1 Vector: AV:N/AC:M/AU:N/C:N/I:N/A:C
Full note on SAP: SAP Support Launchpad note 2001106
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




