Junglewise Threat Intelligence

CVE-2017-5371: SAP Adaptive Server Enterprise OData Server denial of service

CVE-2017-5371 · Severity: high · CVSS 7.5 · Published 2017-01-23

Vendors: SAP.

Executive brief

A vulnerability in the OData Server component of SAP Adaptive Server Enterprise (ASE) allows an attacker to crash the database service remotely. SAP ASE is a high-performance relational database management system used for mission-critical business transactions. An exploit would result in a denial-of-service, disrupting business operations and preventing users from accessing or processing data.

Technical details

A denial-of-service vulnerability exists in the OData Server component of SAP Adaptive Server Enterprise (ASE) version 16.0. The flaw is caused by improper input validation when processing OData requests, allowing a remote, unauthenticated attacker to send a series of specially crafted requests that trigger a process crash. This results in resource exhaustion or a complete service shutdown. The vulnerability is addressed in SAP Security Note 2330422. Affected components include the OData Server binary (typically located in the bin64 directory of the ODATA-16_0 installation).

Affected products

  • SAP Adaptive Server Enterprise (ASE) OData Server 16.0

Timeline

  • 2016-02-02: disclosed: Vulnerability reported to vendor
  • 2016-10-12: advisory: SAP Security Note 2330422 released
  • 2017-01-23: other: NVD publication date

References