Beware! Fully-Functional Exploit Released Online for SAP Solution Manager Flaw
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-6207 | Unauthenticated RCE in SAP Solution Manager 7.2 (CWE-306) CVE-2020-6207 is a missing authentication check (CWE-306) in the User Experience Monitoring service of SAP Solution Manager 7.2, allowing an unauthenticated remote attacker to interact with the service over the network. The flaw is triggered simply by connecting to the unauthenticated service, and CVSS v3.1 scores it 9.8 Critical with network vector, low complexity, and no privileges or user interaction required. A successful attacker achieves remote command execution on the Solution Manager host and complete compromise of every SMDAgent connected to it, with public reporting noting the exploit yields root-level access. Any organization running SAP Solution Manager 7.2 — deployed across the majority of large SAP enterprise landscapes — is affected, particularly where the monitoring service is reachable from untrusted networks. Exploitation is confirmed in the wild: the flaw is in CISA KEV (added 2021-11-03), a fully functional public exploit exists, scanning activity against SAP systems has been reported, and EPSS assigns a 98.3% probability of exploitation within 30 days (100th percentile). Do: Apply SAP's patch for this vulnerability (SAP Security Note 2914509) per vendor instructions, as required by the CISA KEV catalog, and ensure all connected SMDAgents are updated with the Solution Manager. Until patched, restrict or block external access to the Solution Manager monitoring service from untrusted networks, since active scanning of SAP systems has been observed. Check whether your instance exposes the affected service to the internet and hunt for signs of compromise on the SolMan host and connected SMDAgents. | 9.8 | 98% | KEV PoC ×2 |
| moderate≈2,000–5,000 internet-exposed instances (out of tens of thousands of total SolMan deployments worldwide) |
Full article393 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJan 23, 2021
Cybersecurity researchers have warned of a publicly available fully-functional exploit that could be used to target SAP enterprise software.
The exploit leverages a vulnerability, tracked as CVE-2020-6207, that stems from a missing authentication check in SAP Solution Manager (SolMan) version 7.2
SAP SolMan is an application management and administration solution that offers end-to-end application lifecycle management in distributed environments, acting as a centralized hub for implementing and maintaining SAP systems such as ERP, CRM, HCM, SCM, BI, and others.
"A successful exploitation could allow a remote unauthenticated attacker to execute highly privileged administrative tasks in the connected SAP SMD Agents," researchers from Onapsis said, referring to the Solution Manager Diagnostics toolset used to analyze and monitor SAP systems.
The vulnerability, which has the highest possible CVSS base score of 10.0, was addressed by SAP as part of its March 2020 updates.
Exploitation methods leveraging the flaw were later demonstrated at the Black Hat conference last August by Onasis researchers Pablo Artuso and Yvan Genuer to highlight possible attack techniques that could be devised by rogue parties to strike SAP servers and obtain root access.
The critical flaw resided in SolMan's User Experience Monitoring (formerly End-user Experience Monitoring or EEM) component, thus putting every business system connected to the Solution Manager at risk of a potential compromise.
The public availability of a Proof-of-Concept (PoC) exploit code, therefore, leaves unpatched servers exposed to a number of potential malicious attacks, including:
- Shutting down any SAP system in the landscape
- Causing IT to control deficiencies impacting financial integrity and privacy, leading to regulatory compliance violations
- Deleting any data in the SAP systems, causing business disruptions
- Assigning superuser privileges to any existing or new user, allowing those users to run critical operations, and
- Reading sensitive data from the database
"While exploits are released regularly online, this hasn't been the case for SAP vulnerabilities, for which publicly available exploits have been limited," Onapsis researchers said.
"The release of a public exploit significantly increases the chance of an attack attempt since it also expands potential attackers not only to SAP-experts or professionals, but also to script-kiddies or less-experienced attackers that can now leverage public tools instead of creating their own."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/01/beware-fully-functional-released-online.html