Executive brief
A vulnerability in the OData Server component of SAP Adaptive Server Enterprise (ASE) allows an attacker to crash the database service remotely. SAP ASE is a high-performance relational database management system used for mission-critical business transactions. An exploit would result in a denial-of-service, disrupting business operations and preventing users from accessing or processing data.
Technical details
A denial-of-service vulnerability exists in the OData Server component of SAP Adaptive Server Enterprise (ASE) version 16.0. The flaw is caused by improper input validation when processing OData requests, allowing a remote, unauthenticated attacker to send a series of specially crafted requests that trigger a process crash. This results in resource exhaustion or a complete service shutdown. The vulnerability is addressed in SAP Security Note 2330422. Affected components include the OData Server binary (typically located in the bin64 directory of the ODATA-16_0 installation).
Affected products
- SAP Adaptive Server Enterprise (ASE) OData Server 16.0
Timeline
- 2016-02-02: disclosed: Vulnerability reported to vendor
- 2016-10-12: advisory: SAP Security Note 2330422 released
- 2017-01-23: other: NVD publication date
References
- http://packetstormsecurity.com/files/140610/SAP-ASE-ODATA-Server-16-Denial-Of-Service.html
- http://seclists.org/fulldisclosure/2017/Jan/47
- http://www.securityfocus.com/bid/93545
- https://erpscan.io/advisories/erpscan-16-036-sap-ase-odata-server-denial-service/
- https://erpscan.io/press-center/blog/sap-cyber-threat-intelligence-report-october-2016/