Monday, June 24, 2024

90% of SAP Systems Vulnerable to 13-year-old Critical Security Configuration Risk

Critical Security vulnerability impacts 90% of SAP Netweaver installation that if left configured by default. The vulnerability allows attackers to compromise the entire system without even requiring valid SAP credentials.

SAP Netweaver used in many of the business-critical such as payroll, sales, invoicing, manufacturing and others.

A remote unauthenticated Hacker can compromise an SAP Netweaver installation that left with default configuration by just having the network access to the system.
SAP Netweaver

Onapsis Research Labs reported the flaw, according to their report “Attackers can obtain unrestricted access to SAP systems, enabling them to compromise the platform along with all of its information, modify or extract this information or shut the system down.”

Also Read Protecting Big Data with Hadoop: A Cyber Security Protection Guide

The vulnerability impacts up to 90% of companies and affects all the versions of SAP Netweaver versions and still exists with default security settings.

Starting from 2012 SAP NetWeaver Application Server ABAP 7.31 the SAP Gateway Acess control lists is delivered secure by default, but the other SAP services that use the same ACL are not secure by default.

SAP Netweaver

SAP Message Server also implements ACL list to check which IP addresses can register an application server and which ones cannot access. The access control list was controlled by the parameter “ms/acl_info“.

If the parameter “ms/acl_info” left with default configuration and access control list open would allow any host having network access to SAP Message Server can register an application server in the SAP system.

“If the SAP System lacks a secure Message Server ACL configuration, an attacker can exploit this misconfiguration and register a fake Application Server in the SAP system. An attacker only needs to be able to “speak” the message server protocol to register a fake Application Server” reads Onapsis Research report.

By registering a fake application server attackers can compromise the entire system and can launch Man in the Middle attacks to sniff user credentials.

Onapsis has identified, after analyzing multiple SAP customer implementations, that most of them are lacking the proper protection techniques: 9 out of 10 SAP systems are vulnerable to this attack. Researchers provided mitigations steps on Properly configuring SAP Message Server Access control list.


Latest articles

Threat Actor Claiming a 0-day in Linux LPE Via GRUB bootloader

A new threat actor has emerged, claiming a zero-day vulnerability in the Linux GRUB...

LockBit Ransomware Group Claims Hack of US Federal Reserve

The notorious LockBit ransomware group has claimed responsibility for hacking the U.S. Federal Reserve,...

Microsoft Power BI Vulnerability Let Attackers Access Organizations Sensitive Data

A vulnerability in Microsoft Power BI allows unauthorized users to access sensitive data underlying...

Consulting Companies to Pay $11 Million Failing Cybersecurity Requirements

Two consulting companies, Guidehouse Inc. and Nan McKay and Associates, have agreed to pay...

New RAT Malware SneakyChef & SugarGhost Attack Windows Systems

Talos Intelligence has uncovered a sophisticated cyber campaign attributed to the threat actor SneakyChef....

Chinese Winnti Group Intensifies Financially Motivated Attacks

Hackers are increasingly executing financially motivated attacks and all due to the lucrative potential...

PrestaShop Website Under Injection Attack Via Facebook Module

A critical vulnerability has been discovered in the "Facebook" module (pkfacebook) from for...
Guru baran
Guru baran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Free Webinar

API Vulnerability Scanning

71% of the internet traffic comes from APIs so APIs have become soft targets for hackers.Securing APIs is a simple workflow provided you find API specific vulnerabilities and protect them.In the upcoming webinar, join Vivek Gopalan, VP of Products at Indusface as he takes you through the fundamentals of API vulnerability scanning..
Key takeaways include:

  • Scan API endpoints for OWASP API Top 10 vulnerabilities
  • Perform API penetration testing for business logic vulnerabilities
  • Prioritize the most critical vulnerabilities with AcuRisQ
  • Workflow automation for this entire process

Related Articles