SAP patches critical vulnerability that could allow complete system takeover

April 15, 20262 min read1 sources
Share:
SAP patches critical vulnerability that could allow complete system takeover

SAP has released its May 2024 security update, addressing 19 vulnerabilities across its product suite. The most severe patch fixes a critical flaw in the SAP ABAP Server and ABAP Platform that could allow an unauthenticated attacker to gain complete control over affected enterprise systems.

The vulnerability, tracked as CVE-2024-27296, is a missing authorization check with a CVSS score of 9.6 out of 10. According to security firm Onapsis, which discovered and reported the issue, the flaw allows a remote attacker to execute arbitrary ABAP code without any authentication or user interaction. This provides a direct path to compromising the confidentiality, integrity, and availability of the entire system.

A successful exploit could have severe consequences for an organization. An attacker with full control over a core SAP system could access and exfiltrate sensitive data, including financial records, customer information, and intellectual property. They could also disrupt critical business processes, manipulate financial transactions, or deploy additional malware to establish persistent access. Because the attack can be launched remotely over the network, organizations should also ensure their network access controls and VPN configurations for administrators are secure.

The May update also includes several other high-priority patches. These address flaws in SAP Business Technology Platform (BTP) and SAP NetWeaver Application Server for ABAP, which could also lead to unauthorized access if left unpatched.

SAP customers are strongly advised to review SAP Security Note 3432598, which details the critical ABAP vulnerability, and apply all relevant patches immediately to mitigate the risk of exploitation.

Share:

// SOURCES

// RELATED

Most 'AI SOCs' are just faster triage, and that's not enough

Many AI security tools only speed up alert analysis, failing to reduce analyst workload. Experts argue real gains require AI that automates response a

2 min readApr 17

ZionSiphon malware designed to sabotage water treatment systems

A new proof-of-concept malware, ZionSiphon, demonstrates how attackers can sabotage water treatment plants by manipulating industrial control systems.

2 min readApr 17

ThreatsDay bulletin: A deep dive into the Defender 0-day, SonicWall attacks, and a 17-year-old Excel flaw

This week’s threat bulletin is a heavy one. We analyze the critical Microsoft Defender 0-day, a massive SonicWall brute-force campaign, and a 17-year-

6 min readApr 17

Microsoft Defender's 'RedSun' zero-day: A researcher's protest and a threat to Windows systems

A researcher's protest exposed a critical zero-day in Microsoft Defender, allowing attackers full system control. Here's the technical breakdown and h

7 min readApr 17