Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential denial of service in SAP Router, SAP security note 2037492

SAP Note 2037492
SAP Security Note
High priority

SAP security note 2037492, “Potential denial of service in SAP Router”, is a program error note released on October 14, 2014. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Client/Server Technology > Network Interface (BC-CST-NI)
CategoryProgram error
PriorityCorrection with high priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released onOctober 14, 2014

Description

Symptom

A malicious user can remotely exploit the SAProuter process to render it unavailable. This can potentially affect the resources used to serve SAProuter, leading to a denial of service.

Solution

Implement the latest kernel with the included patch. You can download the patch using the Download for SNOTE link or the PDF Version link.

Reason and prerequisites

The issue is caused by a resource exhaustion condition. An attacker can send a specifically crafted request that causes the process to consume excessive resources. This prevents other processes from allocating new resources, making the system unavailable. This condition can be intentionally triggered by an attacker to cause a denial of service.

CVSS

Score 7.1 Vector: AV:N/AC:M/AU:N/C:N/I:N/A:C

Affected components

  • KRNL32NUC: 7.20, 7.20EXT, 7.21, 7.21EXT
  • KRNL32UC: 7.20, 7.20EXT, 7.21, 7.21EXT
  • KRNL64NUC: 7.20, 7.20EXT, 7.21, 7.21EXT, 7.40, 7.41, 7.42
  • KRNL64UC: 7.20, 7.20EXT, 8.04, 7.21, 7.21EXT, 7.40, 7.41, 7.42
  • KERNEL: 7.20 to 7.21, 8.04, 7.40, 7.41, 7.42

Full note on SAP: SAP Support Launchpad note 2037492

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More