SAP Security Note
SAP security note 1687910, “Potential denial of service in DIAG Processor”, released on September 20, 2012. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
This security note has been updated. For more detailed information, see Security Note 1658025.
An attacker can remotely exploit the DIAG Processor, rendering it and potentially the resources used to serve the DIAG Processor unavailable.
Solution
Please apply the patch level of the SAP kernel (disp+work) mentioned in this note at least.
For the installation of the downward compatible kernel (DCK) release 7.20, see SAP Note 1636252 for details.
Reason and prerequisites
The problem is caused by a resource exhaustion condition. An attacker can launch a specifically crafted request that causes the process to consume excessive resources. As a result, no other processes can allocate new resources, rendering the system unavailable. This condition can be intentionally provoked by an attacker to cause a denial of service.
CVSS
Score 5.1 Vector: AV:N/AC:H/AU:N/C:P/I:P/A:P
References
This note refers to
Affected components
- KRNL32NUC: 6.40 to 6.40EX2
- KRNL32NUC: 7.00 to 7.01
- KRNL32NUC: 7.10 to 7.20
- KRNL32NUC: 7.20EXT to 7.20EXT
- KRNL32NUC: 7.21 to 7.21
- KRNL32NUC: 7.21EXT to 7.21EXT
- KRNL32UC: 6.40 to 6.40EX2
- KRNL32UC: 7.00 to 7.01
- KRNL32UC: 7.10 to 7.20
- KRNL32UC: 7.20EXT to 7.20EXT
- KRNL32UC: 7.21 to 7.21
- KRNL32UC: 7.21EXT to 7.21EXT
- KRNL64NUC: 6.40 to 6.40EX2
- KRNL64NUC: 7.00 to 7.01
- KRNL64NUC: 7.10 to 7.20
- KRNL64NUC: 7.20EXT to 7.20EXT
- KRNL64NUC: 7.21 to 7.21
- KRNL64NUC: 7.21EXT to 7.21EXT
- KRNL64UC: 6.40 to 6.40EX2
- KRNL64UC: 7.00 to 7.01
- KRNL64UC: 7.10 to 7.20
- KRNL64UC: 7.20EXT to 7.20EXT
- KRNL64UC: 7.21 to 7.21
- KRNL64UC: 7.21EXT to 7.21EXT
- KERNEL: 6.40 to 6.40
- KERNEL: 7.00 to 7.01
- KERNEL: 7.10 to 7.11
- KERNEL: 7.20 to 7.21
Full note on SAP: SAP Support Launchpad note 1687910
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




