Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Denial of service (DOS) in Message Server, SAP security note 2358972

SAP Note 2358972

SAP security note 2358972, "Denial of service (DOS) in Message Server", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

A vulnerability in the Message Server allows an attacker to prevent legitimate users from accessing the service by either crashing or flooding the service. This Denial of Service (DoS) vulnerability can lead to:

Long response delays and service interruptions, degrading the service quality for legitimate users.

Direct impact on availability.

Solution

Apply at least the Kernel patch named "Fix Memory Leak in Message Server" as mentioned in this SAP Note 2358972.

CVSS

Score 7.5 / 10 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected components

  • KERNEL 7.21 – 7.22
  • KERNEL 7.42
  • KERNEL 7.45
  • KERNEL 7.49
  • KRNL32NUC 7.21
  • KRNL32NUC 7.21EXT
  • KRNL32UC 7.21
  • KRNL32UC 7.21EXT
  • KRNL64NUC 7.21
  • KRNL64NUC 7.21EXT
  • KRNL64NUC 7.42
  • KRNL64NUC 7.22
  • KRNL64NUC 7.22EXT
  • KRNL64NUC 7.49
  • KRNL64UC 7.21
  • KRNL64UC 7.21EXT
  • KRNL64UC 7.42
  • KRNL64UC 7.22
  • KRNL64UC 7.22EXT
  • KRNL64UC 7.49

Full note on SAP: SAP Support Launchpad note 2358972

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More