The Cyber Security Review | Monday, March 15, 2021
Functional exploit code openly available for a maximum severity pre-auth vulnerability affecting default configurations of the SAP Solution Manager (SolMan) element.
Fremont, CA: SAP SolMan is an application lifecycle manager stationed in nearly all SAP environments and intended to assist consolidate the management of all SAP and non-SAP systems within a single interface. SolMan is also employed as an administrative utility for monitoring and managing mission-critical SAP enterprise applications. This significant security blemish is tracked as CVE-2020-6207 and it is produced by a missing authentication verification in the EEM Manager Solman component that could lead to the takeover of connected SAP systems.
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
It can be remotely misused in low complexity strikes by unauthorized attackers with access to the SolMan HTTP(s) port. Even though the vulnerability was revealed and patched by SAP last year, this is the first time that public exploit code was published which drastically lowers the skill level needed by attackers to exploit servers. Attacks victoriously exploiting this vulnerability would endanger virtually all of an organization's SAP applications, business process, and data and will jeopardize all systems operated using the compromised SolMan instance. To make things worse, SolMan is regularly overlooked when executing patching policies and it's generally administered by separate, out-dated policies.
Onapsis did nevertheless highlights the following workable malicious tasks attackers could perform after compromising a SolMan server: Shutting down any SAP system in the landscape, causing IT to control insufficiencies affecting the financial integrity and privacy leading to regulatory compliance violations, and eliminating any data in the SAP systems. Onapsis also identified and published information on publicly available dangerous exploits targeting misconfigured SAP installations.
These exploits revealed approximately 90% out of a predicted total of 1,000,000 SAP production systems to the possible risk of being hacked if misconfigured.
More in News