ZeroHour
Infosecurity Magazinepublished ()ingested Sarah Coble

Exploit Allows Root Access to SAP

criticalVulnerabilityimportance 60CVE-2020-6207

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-6207
Unauthenticated RCE in SAP Solution Manager 7.2 (CWE-306)

CVE-2020-6207 is a missing authentication check (CWE-306) in the User Experience Monitoring service of SAP Solution Manager 7.2, allowing an unauthenticated remote attacker to interact with the service over the network. The flaw is triggered simply by connecting to the unauthenticated service, and CVSS v3.1 scores it 9.8 Critical with network vector, low complexity, and no privileges or user interaction required. A successful attacker achieves remote command execution on the Solution Manager host and complete compromise of every SMDAgent connected to it, with public reporting noting the exploit yields root-level access. Any organization running SAP Solution Manager 7.2 — deployed across the majority of large SAP enterprise landscapes — is affected, particularly where the monitoring service is reachable from untrusted networks. Exploitation is confirmed in the wild: the flaw is in CISA KEV (added 2021-11-03), a fully functional public exploit exists, scanning activity against SAP systems has been reported, and EPSS assigns a 98.3% probability of exploitation within 30 days (100th percentile).

Do: Apply SAP's patch for this vulnerability (SAP Security Note 2914509) per vendor instructions, as required by the CISA KEV catalog, and ensure all connected SMDAgents are updated with the Solution Manager. Until patched, restrict or block external access to the Solution Manager monitoring service from untrusted networks, since active scanning of SAP systems has been observed. Check whether your instance exposes the affected service to the internet and hunt for signs of compromise on the SolMan host and connected SMDAgents.

9.898% KEV PoC ×2
  • SAP Solution Manager (User Experience Monitoring) 7.2
moderate≈2,000–5,000 internet-exposed instances (out of tens of thousands of total SolMan deployments worldwide)
Full article412 words · extracted from infosecurity-magazine.com · click to collapse

A team of enterprise resource planning security experts in Massachusetts have identified a functional exploit affecting SAP that is publicly available.

The exploit was discovered by Onapsis Research Labs on code-hosting platform GitHub, where it had been published by Russian researcher Dmitry Chastuhin on January 14. Researchers said the exploit can be used against SAP SolMan, the administrative system used in every SAP environment that is similar to Active Directory in Windows.

The fully functional exploit abuses United States' National Vulnerability Database listing CVE-2020-6207, a vulnerability in which SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check, does not perform any authentication for a service. This vulnerability results in the complete compromise of all SMDAgents connected to the Solution Manager.

A successful attack exploiting this vulnerability could impact an organization's cybersecurity and regulatory compliance by placing its mission-critical data, SAP applications, and business process at risk.

"While exploits are released regularly online, this hasn't been the case for SAP vulnerabilities, for which publicly available exploits have been limited," wrote Onapsis researchers. 

"The release of a public exploit significantly increases the chance of an attack attempt since it also expands potential attackers not only to SAP-experts or professionals, but also to script-kiddies or less-experienced attackers that can now leverage public tools instead of creating their own."

Because it was created to centralize the management of all SAP and non-SAP systems, SolMan has trusted connections with multiple systems. An attacker that could gain access to SolMan could potentially compromise any business system connected to it. 

"Unfortunately, since it doesn't hold any business information, SAP SolMan is often overlooked in terms of security; in some companies, it does not follow the same patching policy as other systems," noted researchers. 

An attacker with SAP SolMan control could shut down systems, access sensitive data, delete data, cause IT control deficiencies, and assign superuser privileges to any new or existing user. 

"It is not possible to list everything that can potentially be done in the systems if exploited, since having admin privileged control in the systems or running OS commands basically make it limitless for an attacker," wrote researchers.

Sap commented: “SAP Product Security Response Team frequently collaborates with research companies to ensure responsible disclosure of vulnerabilities. The vulnerability in question has been fixed on SAP Security Patch Day – March 2020. We strongly advise our customers to secure their SAP landscape by applying the security note 2890213 from the SAP Support Portal.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/exploit-allows-root-access-to-sap/