On 4th August SAP systems will be hacked on internet in BlackHat USA 2011. SAP systems are used in more than 100 000 world companies to handle business-critical data and processes. The attack is possible due to dangerous vulnerability of the new type, detected by Alexander in J2EE engine of SAP NetWeaver software. For example, it is possible to create a user and assign him to the administrators group using two unauthorized requests to the system. It is possible on systems protected by the two-factor authentication systems, in which it is needed to know secret key and password.
Source: https://thehackernews.com/2011/08/on-4th-august-sap-systems-will-be.html

