SAP Admins Urged to Patch Critical RECON Bug
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-6287 | Missing Authentication (RECON) in SAP NetWeaver AS Java LM Configuration Wizard CVE-2020-6287 is a missing authentication check (CWE-306) in the LM Configuration Wizard component of SAP NetWeaver Application Server Java versions 7.30, 7.31, 7.40 and 7.50. An unauthenticated remote attacker can reach the configuration interface over the network and execute critical configuration tasks without any credentials. This allows the attacker to create administrative users and take full control of the SAP Java system, compromising its confidentiality, integrity and availability. Any organization running SAP NetWeaver AS Java on the affected versions is exposed, especially instances where the LM Configuration Wizard is reachable from untrusted networks. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, carries a 94.7% EPSS probability of exploitation within 30 days, and news reports describe mission-critical SAP applications under active attack. Do: Apply SAP's security updates for NetWeaver AS Java 7.30, 7.31, 7.40 and 7.50 per the vendor's instructions (patches were released in July 2020), prioritizing internet-facing systems given the CISA KEV listing. As an interim mitigation, restrict network access to or disable the LM Configuration Wizard on affected systems. Also audit the system for unexpected or newly created administrative users and review access logs for unauthenticated configuration requests. | 10.0 | 95% | KEV |
| largetens of thousands of installations, with thousands directly internet-exposed |
Full article304 words · extracted from infosecurity-magazine.com · click to collapse
The US government is urging SAP customers to patch a critical vulnerability published earlier this week, which could affect as many as 40,000 customers.
Released as part of the software giant’s July patch update round, CVE-2020-6287 affects the SAP NetWeaver Application Server (AS) Java component LM Configuration Wizard.
According to an alert from the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency (CISA), the bug is introduced thanks to a lack of authentication in the component.
“If successfully exploited, a remote, unauthenticated attacker can obtain unrestricted access to SAP systems through the creation of high-privileged users and the execution of arbitrary operating system commands with the privileges of the SAP service user account (adm), which has unrestricted access to the SAP database and is able to perform application maintenance activities, such as shutting down federated SAP applications,” it explained.
“The confidentiality, integrity, and availability of the data and processes hosted by the SAP application are at risk by this vulnerability.”
As SAP NetWeaver AS Java supports a large range of SAP applications, the potential impact is severe. These include: SAP Enterprise Resource Planning, Product Lifecycle Management, Customer Relationship Management, Supply Chain Management, Supplier Relationship Management, NetWeaver Business Warehouse, Business Intelligence, NetWeaver Mobile Infrastructure, Enterprise Portal, Process Orchestration/Process Integration, Solution Manager, NetWeaver Development Infrastructure, Central Process Scheduling, NetWeaver Composition Environment, and Landscape Manager.
Onapsis Research Labs, which discovered the vulnerability, named it RECON and warned that the CVSS 10.0 bug could affect more than 40,000 global SAP customers.
It could allow remote attackers to steal PII from employees, customers and suppliers, delete or modify financial records, change banking details, disrupt operations and much more, the vendor claimed.
“The business impact of a potential exploit targeting RECON could be financial loss, compliance violations and reputation damage for the organization experiencing a cyber-attack,” it added.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisa-patch-critical-sap-recon-bug/