Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Update 1 to security note 1800603, SAP security note 2074889

SAP Note 2074889
SAP Security Note
HotNews

SAP security note 2074889, "Update 1 to security note 1800603", is a note released on November 11, 2014. Below are the symptom, SAP recommended solution and the affected software components.

ComponentBasis Components > Client/Server Technology > Message Service (BC-CST-MS)
PriorityHotNews
TypeSAP Security Note
StatusReleased for Customer
Released onNovember 11, 2014
LanguageEnglish

Description

Symptom

Update 1 to SAP Security Note 1800603 for kernel releases 720 and 721.

An attacker can exploit Message Server to take complete control of the product, including viewing, changing, or deleting data.

Solution

Please apply the kernel patch level mentioned in SAP Note 1800603.

At least:

  • Kernel 720 PL620
  • Kernel 721 PL318

Reason and prerequisites

A buffer overflow vulnerability exists in Message Server, allowing an attacker to inject and execute code or cause the product to terminate.

CVSS

Score 10.0 Vector: AV:N/AC:L/AU:N/C:C/I:C/A:C

References

Affected components

  • SAP KERNEL 7.20, 32-Bit and 64-Bit
  • SAP KERNEL 7.21, 32-Bit and 64-Bit
  • Both Unicode and non-Unicode versions

Full note on SAP: SAP Support Launchpad note 2074889

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More