Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential denial of service in jstart, SAP security note 2259547

SAP Note 2259547
SAP Security Note
High priority

SAP security note 2259547, “Potential denial of service in jstart”, is a note released on 14.03.2016. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > NetWeaver Application Server Java > Startup Framework
PriorityCorrection with high priority
TypeSAP Security Note
Version6
StatusReleased for Customer
Released on14.03.2016
LanguageEnglish

Description

Symptom

An attacker can remotely exploit jstart, rendering it, and potentially the resources that are used to serve jstart, unavailable.

Solution

Apply the patch specified in this SAP Note 2259547.

By applying this patch, the "NetWeaver Administrator Heap Dump Analysis" will be affected. For details and the solution, refer to SAP Note 2283299.

Reason and prerequisites

The problem is caused by a resource exhaustion condition. An attacker can launch a specifically crafted request that causes the process to consume excessive resources. As a result, no other processes can allocate new resources, rendering the system unavailable. This condition can be intentionally provoked by an attacker to cause a denial of service.

CVSS

Score 7.5 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected components

  • SAP KERNEL 7.21 to 7.47 (various versions)

Full note on SAP: SAP Support Launchpad note 2259547

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More