Critical Flaws Reported in Sage X3 Enterprise Management Software
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-7388 +1 in the same advisory: …7387 | Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential validation. While exploiting this does require knowledge of the installation path, that information can be learned by exploiting CVE-2020-7387. This issue was fixed in AdxAdmin 93.2.53, which ships with updates for on-premises versions of Sage X3 including Version 9 (components shipped with Syracuse 9.22.7.2 and later), Sage X3 HR & Payroll Version 9 (those components that ship with Syracuse 9.24.1.3), Version 11 (components shipped with Syracuse 11.25.2.6 and later), and Version 12 (components shipped with Syracuse 12.10.2.8 and later) of Sage X3. Other on-premises versions of Sage X3 are unsupported by the vendor. NVD description · AI analysis pending | 9.8 group max | 69% | PoC |
| — | |
| CVE-2020-7389 +1 in the same advisory: …7390 | Sage X3 System CHAINE Variable Script Command Injection. Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production. NVD description · AI analysis pending | 7.2 group max | 2% | PoC |
| — |
Full article500 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJul 08, 2021
Four security vulnerabilities have been uncovered in the Sage X3 enterprise resource planning (ERP) product, two of which could be chained together as part of an attack sequence to enable adversaries to execute malicious commands and take control of vulnerable systems.
These issues were discovered by researchers from Rapid7, who notified Sage Group of their findings on Feb. 3, 2021. The vendor has since rolled out fixes in recent releases for Sage X3 Version 9 (Syracuse 9.22.7.2), Sage X3 HR & Payroll Version 9 (Syracuse 9.24.1.3), Sage X3 Version 11 (Syracuse 11.25.2.6), and Sage X3 Version 12 (Syracuse 12.10.2.8) that were shipped in March.
The list of vulnerabilities is as follows -
- CVE-2020-7388 (CVSS score: 10.0) - Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component
- CVE-2020-7389 (CVSS score" 5.5) - System "CHAINE" Variable Script Command Injection (No fix planned)
- CVE-2020-7387 (CVSS score: 5.3) - Sage X3 Installation Pathname Disclosure
- CVE-2020-7390 (CVSS score: 4.6) - Stored XSS Vulnerability on 'Edit' Page of User Profile
"When combining CVE-2020-7387 and CVE-2020-7388, an attacker can first learn the installation path of the affected software, then use that information to pass commands to the host system to be run in the SYSTEM context," the researchers said. "This can allow an attacker to run arbitrary operating system commands to create Administrator level users, install malicious software, and otherwise take complete control of the system for any purpose."
The most severe of the issues is CVE-2020-7388, which takes advantage of an administrative service that's accessible over the internet to craft malicious requests with the goal of running arbitrary commands on the server as the "NT AUTHORITY/SYSTEM" user. The service in question is used for remote management of the Sage ERP solution through the Sage X3 Console.
Separately, the 'Edit' page associated with user profiles in the Sage X3 Syracuse web server component is vulnerable to a stored XSS attack (CVE-2020-7390), enabling the execution of arbitrary JavaScript code during 'mouseOver' events in the 'First name', 'Last name', and 'Email' fields.
"If successful, however, this vulnerability could allow a regular user of Sage X3 to execute privileged functions as a currently logged-in administrator or capture administrator session cookies for later impersonation as a currently-logged-in administrator," the researchers said.
Successful exploitation of CVE-2020-7387, on the other hand, results in the exposure of Sage X3 installation paths to an unauthorized user, while CVE-2020-7389 concerns a missing authentication in Syracuse development environments that could be used to gain code execution via command injection.
"Generally speaking, Sage X3 installations should not be exposed directly to the internet, and should instead be made available via a secure VPN connection where required," the researchers noted in the disclosure. "Following this operational advice effectively mitigates all four vulnerabilities, though customers are still urged to update according to their usual patch cycle schedules."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/07/critical-flaws-reported-in-sage-x3.html