Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential denial of service in SAP Kernel (Diag parser), SAP security note 1791238

SAP Note 1791238
Medium priority

SAP security note 1791238, "Potential denial of service in SAP Kernel (Diag parser)", released on May 14, 2013. Below are the symptom and SAP recommended solution.

ComponentBasis Components > ABAP Runtime Environment – ABAP Language Issues Only > Dynpro and CUA engine
PriorityCorrection with medium priority
StatusReleased for Customer
Released onMay 14, 2013

Description

Symptom

An attacker can remotely exploit the Diag Parser in the kernel, rendering it, and potentially the resources that are used to serve the Diag Parser, unavailable.

Solution

Apply the appropriate support package patch as specified below to mitigate the vulnerability.

Reason and prerequisites

An attacker can trigger a condition in which the process creates a core dump, causing it to restart. This causes the entire machine to become unresponsive until the process is available again. An attacker can use this flaw to launch a denial-of-service (DoS) attack. This condition can be intentionally provoked by an attacker to cause a denial of service.

CVSS

Score 7.1 Vector: AV:N/AC:M/AU:N/C:N/I:N/A:C

Full note on SAP: SAP Support Launchpad note 1791238

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More