Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential remote termination of running processes in SAP HANA text engine, SAP security note 2175928

SAP Note 2175928
High priority

SAP security note 2175928, "Potential Remote Termination of Running Processes in SAP HANA Text Engine", released on August 11, 2015. Below are the symptom and SAP recommended solution.

ComponentSAP HANA Text Engine (HAN-DB-ENG-TXT)
PriorityCorrection with high priority
StatusReleased for Customer
Released onAugust 11, 2015

Description

Symptom

An attacker can remotely exploit the text engine in SAP HANA to manually terminate the index server. This can render the application unusable until it is restarted manually.

Solution

  • SPS09: Revision 95 or later
  • SPS08: Revision 85.05 or later

Reason and prerequisites

The issue is caused by a memory overflow that forces the process to terminate. An attacker can create a condition where the process attempts to read outside its memory space, resulting in a memory protection fault and subsequent process termination.

CVSS

Score 6.8 Vector: Network (N), Low (L) Complexity, Single (S) Authentication, Complete (C) Availability Impact

Full note on SAP: SAP Support Launchpad note 2175928

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More