SAP Security Note
HotNews
SAP security note 2074889, "Update 1 to security note 1800603", is a note released on November 11, 2014. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Update 1 to SAP Security Note 1800603 for kernel releases 720 and 721.
An attacker can exploit Message Server to take complete control of the product, including viewing, changing, or deleting data.
Solution
Please apply the kernel patch level mentioned in SAP Note 1800603.
At least:
- Kernel 720 PL620
- Kernel 721 PL318
Reason and prerequisites
A buffer overflow vulnerability exists in Message Server, allowing an attacker to inject and execute code or cause the product to terminate.
CVSS
Score 10.0 Vector: AV:N/AC:L/AU:N/C:C/I:C/A:C
References
Affected components
- SAP KERNEL 7.20, 32-Bit and 64-Bit
- SAP KERNEL 7.21, 32-Bit and 64-Bit
- Both Unicode and non-Unicode versions
Full note on SAP: SAP Support Launchpad note 2074889
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
