Blog | G5 Cyber Security

Hacking SAP CRM by chaining 2 vulnerabilities in SAP NetWeaver AS Java

Security experts at ERPScan explained that chaining 2 flaws recently patched it is possible to hack SAP CRM systems and access sensitive data. The flaws are a directory traversal issue and a log injection vulnerability, their combination could lead to information disclosure, privilege escalation, and full compromise SAP CRMs. The experts provided details about the full attack scenario is that is composed of the following steps: Using special request, he or she can inject a malicious code (a web shell) into the log file and call it anonymously from a remote web server.”]

Source: http://securityaffairs.co/wordpress/70311/hacking/hacking-sap-crm.html

Exit mobile version