SAP security note 2127995, "Potential remote termination of running processes in Content Server". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can remotely exploit SAP Content Server and can potentially terminate it.
Solution
Please implement the following manual activities:
Please refer to note 514500 and update to SAP Content Server 6.50 SP03.
Reason and prerequisites
The issue is caused by a memory corruption that leads to the termination of the process. An attacker can provoke a condition where the process attempts to read outside its memory space, causing a memory protection fault. As a result, the system terminates the process, rendering the application unusable until it is manually restarted.
CVSS
Score 8.3 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:C
References
This note refers to
Affected components
- CONTSERV 6.50
Full note on SAP: SAP Support Launchpad note 2127995
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



