The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive 22-01, mandating that government departments and agencies remediate specific vulnerabilities known to be actively exploited. This directive highlights six critical SAP vulnerabilities that pose significant risks to information systems, requiring remediation to ensure landscape security.
What is the CISA Known Exploited Vulnerabilities (KEV) Catalog?
Unlike standard CVSS-based scoring, which assesses theoretical risk, the CISA Known Exploited Vulnerabilities (KEV) Catalog focuses on vulnerabilities with confirmed active threats. The directive compels organizations to prioritize these specific CVEs, as they are actively targeted by malicious actors.
Vulnerabilities Requiring Immediate Remediation
The following six vulnerabilities are currently listed in the KEV catalog for SAP applications:
| CVE | Impact | SAP Note |
|---|---|---|
| CVE-2010-5326 | Authentication bypass / RCE in NetWeaver AS Java | 1445998 |
| CVE-2016-3976 | Directory traversal in AS Java | 2234971 |
| CVE-2016-9563 | Denial of Service (DoS) in AS Java | 2296909 |
| CVE-2018-2380 | Directory traversal in SAP CRM | 2547431 |
| CVE-2020-6207 | Missing authentication in Solution Manager | 2890213 |
| CVE-2020-6287 | RECON vulnerability in AS Java | 2934135 |
How to secure your SAP environment
To comply with the directive and protect your critical assets, organizations should:
- Review and Patch: Apply the relevant SAP notes listed above to all affected systems.
- Automate Discovery: Use the Cybersecurity Extension for SAP to automate the discovery of systems vulnerable to these specific CVEs.
- Monitor for Exploits: Implement logging and monitoring to detect exploit signatures associated with these vulnerabilities. The Cybersecurity Extension for SAP provides mechanisms to investigate and respond to these specific threats.
Frequently Asked Questions
Why does CISA prioritize these vulnerabilities?
CISA prioritizes these vulnerabilities because they are actively exploited by threat actors. Unlike traditional scoring, the KEV catalog focuses on real-world threat intelligence, meaning these flaws are currently being used to compromise systems.
What are the risks of CVE-2020-6287 (RECON)?
The RECON vulnerability in the LM Configuration Wizard allows unauthenticated attackers to perform administrative functions, such as creating new privileged users, effectively granting them full control over the SAP Java stack.
How does the Cybersecurity Extension for SAP assist with compliance?
The Cybersecurity Extension for SAP automates the identification of vulnerable systems and monitors logs for signs of exploit attempts. It serves as a comprehensive tool for vulnerability management across SAP applications, databases, and host layers.