Unauthenticated Memory Corruption via DIAG Protocol in SAP NetWeaver AS ABAP
SAP NetWeaver AS ABAP and ABAP Platform (DIAG Protocol)
Unauthenticated memory corruption in the DIAG protocol hits a port that every ABAP system has open on the internal network. Most SAP landscapes assume DIAG is internal-only — which is fine — but lateral movement from any compromised internal host becomes trivial exploitation. Kernel patch, restart required; coordinate with your BASIS team now.
Vulnerability Detail
Improper boundary validation in DIAG protocol parsing within SAP NetWeaver Application Server ABAP allows an unauthenticated remote attacker to send a specially crafted network packet that triggers memory corruption. Successful exploitation can lead to disclosure of sensitive information or complete system crash — and under favourable conditions, arbitrary code execution. DIAG is the native SAP GUI network protocol used by all SAPGUI connections.
Workaround
Block external access to DIAG protocol ports (32xx/33xx) at the network perimeter. DIAG should never be accessible from the internet — if it is, close it immediately regardless of this patch.
Patch Action
Apply SAP Note 3714806 (kernel-level patch). A system restart is required. Verify affected kernel versions in the official Note.
Affected Versions
Patch Info