SAP security note 1893561, “Potential denial of service in SAP Sybase ASE”, is a note. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can launch a specifically crafted request causing the SAP Sybase ASE process on Microsoft Windows to be terminated. This results in SAP Sybase ASE becoming unavailable until the process is manually rebooted. This condition can be intentionally provoked by an attacker to cause a denial of service (DoS).
Solution
This issue has been fixed in the following SAP Sybase ASE versions on Microsoft Windows:
- SAP Sybase ASE 15.7 SP100
- SAP Sybase ASE 15.7 ESD#4
Install the fixed SAP Sybase ASE versions most appropriate for your production environments.
CVSS
Score 6.3 Vector: AV:N/AC:M/AU:S/C:N/I:N/A:C
Full note on SAP: SAP Support Launchpad note 1893561
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



