Medium priority
SAP security note 1791238, "Potential denial of service in SAP Kernel (Diag parser)", released on May 14, 2013. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can remotely exploit the Diag Parser in the kernel, rendering it, and potentially the resources that are used to serve the Diag Parser, unavailable.
Solution
Apply the appropriate support package patch as specified below to mitigate the vulnerability.
Reason and prerequisites
An attacker can trigger a condition in which the process creates a core dump, causing it to restart. This causes the entire machine to become unresponsive until the process is available again. An attacker can use this flaw to launch a denial-of-service (DoS) attack. This condition can be intentionally provoked by an attacker to cause a denial of service.
CVSS
Score 7.1 Vector: AV:N/AC:M/AU:N/C:N/I:N/A:C
Full note on SAP: SAP Support Launchpad note 1791238
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



