SAP security note 1469804, "Potential denial of service in sapstartsrv", is a program error note released on September 14, 2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A remote denial of service (DoS) vulnerability has been identified in the sapstartsrv process. This vulnerability allows a malicious user to exploit a memory corruption flaw, causing the sapstartsrv process to terminate unexpectedly. As a result, the process becomes unavailable, and the system cannot handle sapcontrol requests, effectively rendering the SAP system inaccessible.
Solution
Apply the appropriate kernel patch based on your SAP system version:
- 6.40: Patch 319
- 7.00: Patch 244
- 7.01: Patch 074
- 7.10: Patch 182
- 7.11: Patch 068
Affected components
- KRNL32NUC: Versions 6.40 to 6.40EX2, 7.00 to 7.01, 7.10 to 7.11
- KRNL32UC: Versions 6.40 to 6.40EX2, 7.00 to 7.01, 7.10 to 7.11
- KRNL64NUC: Versions 6.40 to 6.40EX2, 7.00 to 7.01, 7.10 to 7.11
- KRNL64UC: Versions 6.40 to 6.40EX2, 7.00 to 7.01, 7.10 to 7.11
- KERNEL: Versions 6.40, 7.00 to 7.01, 7.10 to 7.11
Full note on SAP: SAP Support Launchpad note 1469804
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
