Multiple Sage X3 vulnerabilities expose systems to hack
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-7388 +1 in the same advisory: …7387 | Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. Sage X3 Unauthenticated Remote Command Execution (RCE) as SYSTEM in AdxDSrv.exe component. By editing the client side authentication request, an attacker can bypass credential validation. While exploiting this does require knowledge of the installation path, that information can be learned by exploiting CVE-2020-7387. This issue was fixed in AdxAdmin 93.2.53, which ships with updates for on-premises versions of Sage X3 including Version 9 (components shipped with Syracuse 9.22.7.2 and later), Sage X3 HR & Payroll Version 9 (those components that ship with Syracuse 9.24.1.3), Version 11 (components shipped with Syracuse 11.25.2.6 and later), and Version 12 (components shipped with Syracuse 12.10.2.8 and later) of Sage X3. Other on-premises versions of Sage X3 are unsupported by the vendor. NVD description · AI analysis pending | 9.8 group max | 69% | PoC |
| — | |
| CVE-2020-7389 +1 in the same advisory: …7390 | Sage X3 System CHAINE Variable Script Command Injection. Sage X3 System CHAINE Variable Script Command Injection. An authenticated user with developer access can pass OS commands via this variable used by the web application. Note, this developer configuration should not be deployed in production. NVD description · AI analysis pending | 7.2 group max | 2% | PoC |
| — |
Full article550 words · extracted from securityaffairs.com · click to collapse

Rapid7 researchers discovered security vulnerabilities in the Sage X3 ERP product that could allow to take control of vulnerable systems.
Researchers from Rapid7 discovered a total of four security vulnerabilities in the Sage X3 enterprise resource planning (ERP) solution. Chaining two of the vulnerabilities discovered by the expert, an attacker could execute malicious commands and take control of vulnerable systems.
The experts reported the flaw to the software vendor in February 2021 and the company addressed them with the release of Sage X3 Version 9 (Syracuse 9.22.7.2), Sage X3 HR & Payroll Version 9 (Syracuse 9.24.1.3), Sage X3 Version 11 (Syracuse 11.25.2.6), and Sage X3 Version 12 (Syracuse 12.10.2.8).
The vulnerabilities are reported in the following table, the first two are protocol-related issues involving remote administration of Sage X3, while the remaining ones are issues that affect the web application.
| CVE Identifier | CWE Identifier | CVSS score (Severity) | Remediation |
|---|---|---|---|
| CVE-2020-7388 | CWE-290: Unauthenticated Command Execution Bypass by Spoofing in AdxAdmin | 10.0 (Critical) | Update available |
| CVE-2020-7387 | CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in AdxAdmin | 5.3 (Medium) | Update available |
| CVE-2020-7389 | CWE-306 Missing Authentication for Critical Function in Developer Environment in Syracuse | 5.5 (Medium) | No fix planned, as this is a development function and not a production function. |
| CVE-2020-7390 | CWE-79: Persistent Cross-Site Scripting (XSS) in Syracuse | 4.6 (Medium) | Update available (note, this affects V12 only, unlike the other issues which affects V9 and V11 as well) |
Upon combining the CVE-2020-7387 and CVE-2020-7388 flaws, an attacker can gather info on the installation, then use that information to pass commands to the host system to be run in the SYSTEM context.
“When combining CVE-2020-7387 and CVE-2020-7388, an attacker can first learn the installation path of the affected software, then use that information to pass commands to the host system to be run in the SYSTEM context. This can allow an attacker to run arbitrary operating system commands to create Administrator level users, install malicious software, and otherwise take complete control of the system for any purpose.” reads the post published by Rapid7.
The most severe of the vulnerabilities is the CVE-2020-7388 issue which takes advantage of an administrative service for remote management of the Sage ERP solution through the Sage X3 Console that is accessible online.
An attacker could send maliciously crafted requests to run arbitrary commands on the server as the “NT AUTHORITY/SYSTEM” user.
The exploitation of CVE-2020-7387 could allow an unauthorized attacker to access info about Sage X3 installation paths. The CVE-2020-7389 is a missing authentication in Syracuse development environments that could allow attackers to execute arbitrary code via command injection.
“Some web application scripts that allowed the use of the ‘System’ function could be paired with the ‘CHAINE’ variable in order to execute arbitrary commands, including those sourced from a remote SMB share. The page can be reached via the menu prompts Development -> Script dictionary -> Scripts. Note that, according to the vendor, this functionality should only be available in development environments, and not production environments.” continues the report.
Experts pointed out that Sage X3 installations should not be exposed directly to the internet, they recommend only allow remote access via VPN connection where required.
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, SAGE)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/119884/security/sage-x3-erp-flaws.html