SAP security note 2233136, “Potential termination of running processes triggered by IMPORT statement”. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Authenticated attackers with the IMPORT privilege can exploit HANA to manually terminate running processes.
Solution
The issue is fixed with revision 102.02 (for SPS10). SPS11 is not affected. Update to these or later revisions.
Workaround:
- Limit the IMPORT authorization to trusted applications/users.
- Import binary files only from trusted sources, such as unmodified files exported from an SAP HANA system.
Reason and prerequisites
Specially crafted input might cause the process to terminate. An authenticated attacker with the IMPORT system privilege can provoke a condition where the process attempts to read invalid data, resulting in the termination of the indexserver process. This renders the application unusable until it is restarted automatically.
CVSS
Score 4.9 Vector: AV:N/AC:H/Au:S/C:N/I:N/A:C
Affected components
- HDB 1.00 to 1.00
Full note on SAP: SAP Support Launchpad note 2233136
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



