Get a Pentest and security assessment of your IT network.

News

Hacking SAP CRM by chaining 2 vulnerabilities in SAP NetWeaver AS Java

Security experts at ERPScan explained that chaining 2 flaws recently patched it is possible to hack SAP CRM systems and access sensitive data. The flaws are a directory traversal issue and a log injection vulnerability, their combination could lead to information disclosure, privilege escalation, and full compromise SAP CRMs. The experts provided details about the full attack scenario is that is composed of the following steps: Using special request, he or she can inject a malicious code (a web shell) into the log file and call it anonymously from a remote web server.”]

Source: http://securityaffairs.co/wordpress/70311/hacking/hacking-sap-crm.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Who and why is attacking companies in the Nordic Countries?

News

Social Networks Part 1 Who exactly are you disclosing your life story to?