Mass Disclosure of Vulnerabilities in SAP from ERPScan Specialists
This month ERPScan specialists published eight vulnerabilities of different criticality found in SAP products.
The vulnerabilities represented almost all risks from the OWASP Top 10, from path traversal and XSS to authorization bypass and code injection - and were published on the ERPScan.com site.
Every month we publish information about vulnerabilities found in SAP products by our specialists, but this was a really productive month.
We have to say that SAP has increased the rate of reaction against vulnerabilities found by third-party researchers. Right now they much are faster at finding solutions for these vulnerabilities, and it makes the system more secure.
However there is still a huge problem connected with administrators' ignorance and the complexity of installing updates.
That's why according to our surveys, a huge amount of SAP systems - including those available via internet - contain vulnerabilities which were already closed by SAP.
"These companies can be very easy targets for attackers," said Alexander Polyakov, the CTO of ERPScan.
Details of the vulnerabilities can be found here: