ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

New Highly-Critical SAP Bug Could Let Attackers Take Over Corporate Servers

criticalVulnerability exploited in the wildimportance 60CVE-2020-6287

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-6287
Missing Authentication (RECON) in SAP NetWeaver AS Java LM Configuration Wizard

CVE-2020-6287 is a missing authentication check (CWE-306) in the LM Configuration Wizard component of SAP NetWeaver Application Server Java versions 7.30, 7.31, 7.40 and 7.50. An unauthenticated remote attacker can reach the configuration interface over the network and execute critical configuration tasks without any credentials. This allows the attacker to create administrative users and take full control of the SAP Java system, compromising its confidentiality, integrity and availability. Any organization running SAP NetWeaver AS Java on the affected versions is exposed, especially instances where the LM Configuration Wizard is reachable from untrusted networks. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, carries a 94.7% EPSS probability of exploitation within 30 days, and news reports describe mission-critical SAP applications under active attack.

Do: Apply SAP's security updates for NetWeaver AS Java 7.30, 7.31, 7.40 and 7.50 per the vendor's instructions (patches were released in July 2020), prioritizing internet-facing systems given the CISA KEV listing. As an interim mitigation, restrict network access to or disable the LM Configuration Wizard on affected systems. Also audit the system for unexpected or newly created administrative users and review access logs for unauthenticated configuration requests.

10.095% KEV
  • SAP NetWeaver Application Server Java (LM Configuration Wizard) 7.30, 7.31, 7.40, 7.50
largetens of thousands of installations, with thousands directly internet-exposed
Full article419 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJul 14, 2020

SAP has patched a critical vulnerability impacting the LM Configuration Wizard component in NetWeaver Application Server (AS) Java platform, allowing an unauthenticated attacker to take control of SAP applications.

The bug, dubbed RECON and tracked as CVE-2020-6287, is rated with a maximum CVSS score of 10 out of 10, potentially affecting over 40,000 SAP customers, according to cybersecurity firm Onapsis, which uncovered the flaw.

"If successfully exploited, a remote, unauthenticated attacker can obtain unrestricted access to SAP systems through the creation of high-privileged users and the execution of arbitrary operating system commands with the privileges of the SAP service user account, which has unrestricted access to the SAP database and is able to perform application maintenance activities, such as shutting down federated SAP applications," the US Cybersecurity and Infrastructure Security Agency (CISA) said in an advisory.

"The confidentiality, integrity, and availability of the data and processes hosted by the SAP application are at risk by this vulnerability," it added.

The vulnerability is present by default in SAP applications running on top of SAP NetWeaver AS Java 7.3 and newer (up to SAP NetWeaver 7.5), putting several SAP business solutions at risk, including but not limited to SAP Enterprise Resource Planning, SAP Product Lifecycle Management, SAP Customer Relationship Management, SAP Supply Chain Management, SAP Business Intelligence, and SAP Enterprise Portal.

According to Onapsis, RECON is caused due to a lack of authentication in the web component of the SAP NetWeaver AS for Java, thus granting an attacker to perform high-privileged activities on the susceptible SAP system.

"A remote, unauthenticated attacker can exploit this vulnerability through an HTTP interface, which is typically exposed to end users and, in many cases, exposed to the internet," CISA said.

By exploiting the flaw to create a new SAP user with maximum privileges, the intruder can compromise SAP installations to execute arbitrary commands, such as modifying or extracting highly sensitive information as well as disrupting critical business processes.

Although there's no evidence of any active exploitation of the vulnerability, CISA cautioned that the patches' availability could make it easier for adversaries to reverse-engineer the flaw to create exploits and target unpatched systems.

Given the severity of RECON, it's recommended that organizations apply critical patches as soon as possible and scan SAP systems for all known vulnerabilities and analyze systems for malicious or excessive user authorizations.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2020/07/sap-netweaver-vulnerability.html