Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential denial of service in saposcol, SAP security note 2220064

SAP Note 2220064
Medium priority

SAP security note 2220064, “Potential denial of service in saposcol”, was released on December 8, 2015. Below are the symptom and SAP recommended solution.

ComponentBasis Components > Computer Center Management System (CCMS) > CCMS Monitoring & Alerting > Operating System Monitoring Tool (BC-CCM-MON-OS)
PriorityCorrection with medium priority
StatusReleased for Customer
Released onDecember 8, 2015

Description

Symptom

An attacker can locally exploit the NT version of saposcol, potentially rendering it and the resources used to serve saposcol unavailable.

An attacker can trigger a condition where the process enters an endless loop, consuming all available processing time. This causes the entire machine to become unresponsive until the process is manually terminated. This vulnerability can be exploited to launch a denial-of-service (DoS) attack.

Solution

Update your SapHostAgent 7.21 to the respective patch level.

Reason and prerequisites

The issue is caused by a resource exhaustion condition. An attacker can send a specifically crafted request that causes the saposcol process to consume excessive resources. Consequently, other processes cannot allocate new resources, making the system unavailable.

CVSS

Score 3.8 Vector: AV:L/AC:H/Au:S/C:N/I:N/A:C

Full note on SAP: SAP Support Launchpad note 2220064

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More