SAP security note 2476937, "Potential Denial of Service vulnerability in SAP Standalone Enqueue Server", is a program error note released on 10.10.2017. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can remotely exploit the SAP Standalone Enqueue Server, rendering it unavailable and potentially making the resources used to serve the SAP Standalone Enqueue Server inaccessible.
Solution
SAP has addressed this vulnerability by improving the handling of parameters when accepting new connections. To apply the correction, ensure that you apply the ENSERVER package at least at the patch level mentioned in this SAP Note.
Reason and prerequisites
The issue arises from a resource exhaustion condition. An attacker can send a specifically crafted request that causes the process to consume excessive resources, leading to system unavailability.
CVSS
Score 7.5 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Full note on SAP: SAP Support Launchpad note 2476937
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
