THANK YOU FOR SUBSCRIBING
Enterprise Security Magazine | Wednesday, July 22, 2020
A critical vulnerability, carrying a high severity on the CvSS bug-severity scale, has been disclosed for SAP customers. The exploitation of the bug can enable an attacker to lift sensitive information, delete files, execute code, and carry out sabotage, and more.
FREMONT, CA: SAPs widely deployed collection of enterprise resource planning (ERP) software is leveraged to manage their financials, logistics, customer-facing organizations, human resources, and other business areas because the systems contain a high amount of sensitive information. Piyush Pandey, CEO at Appsian, company offering ERP security solutions, says, "ERP security and visibility had primarily focused on application level configuration vulnerabilities and/or transaction monitoring. The CvSS bug exploit is taking advantage of a very specific visibility gap and that's the lack of fine-grained data access visibility. Understanding exactly what is happening around the data itself is becoming a glaring hole that leaves many ERP customers exposed to exploits. Clearly the ERP data security conversation needs to shift to how granular a view can you get into data access and usage? Can you monitor and be alerted to even minor changes? If the answer is no then immediate action is required."
SAP has patched a crucial vulnerability impacting the LM Configuration Wizard component in NetWeaver Application Server (AS) Java platform, enabling an unauthenticated attacker to overtake the control of the SAP applications. According to the cybersecurity firm, the bug, dubbed RECON and tracked as CVE-2020-6287, is rated with a maximum CVSS score of 10 out of 10, potentially affecting over 40,000 SAP customers Onapsis, which uncovered the flaw.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
Check This Out: Top SAP Consulting Companies
The vulnerability is prevalent by default in SAP applications running on top of SAP NetWeaver AS Java 7.3 and newer, pushing various SAP business solutions at risk, SAP Customer Relationship Management, including but not limited to SAP Enterprise Resource Planning, SAP Product Lifecycle Management, SAP Business Intelligence, SAP Supply Chain Management, and SAP Enterprise Portal.
By leveraging the flaw to create a new SAP user with the highest privileges, the intruder can compromise SAP installations to execute arbitrary commands, such as modifying or extracting highly sensitive information and disrupting critical business processes.
Although there's no evidence of any active exploitation of the vulnerability, CISA cautioned that the patches' availability could make it easier for adversaries to reverse-engineer the flaw to create exploits and target unpatched systems.
Given the severity of RECON, it's recommended that organizations apply critical patches as soon as possible and scan SAP systems for all known vulnerabilities and analyze methods for malicious or excessive user authorizations.
More in News