SAP Security Note
Low priority
SAP security note 2223688, “Potential Denial of Service in Message Server”, is a program error note released on 08.03.2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can remotely exploit the message server, rendering it, and potentially the resources that are used to serve Message Server, unavailable.
Solution
Use the kernel mentioned in this SAP Note.
Reason and prerequisites
The problem is caused by a resource exhaustion condition. An attacker can launch a specifically crafted request that causes the process to consume excessive resources. As a result, no other processes can allocate new resources, rendering the system unavailable. This condition can be intentionally provoked by an attacker to cause a denial of service.
Affected components
- KRNL32NUC: 7.21, 7.21EXT
- KRNL32UC: 7.21, 7.21EXT
- KRNL64NUC: 7.21, 7.21EXT, 7.42, 7.22, 7.22EXT
- KRNL64UC: 7.21, 7.21EXT, 7.42, 7.22, 7.22EXT
- KERNEL: 7.21 to 7.22, 7.42, 7.45
Full note on SAP: SAP Support Launchpad note 2223688
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
