CISA Directive: Remediating Actively Exploited SAP Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive 22-01, mandating that government departments and agencies remediate specific vulnerabilities known to be actively exploited. This directive highlights six critical SAP vulnerabilities that pose significant risks to information systems, requiring remediation to ensure landscape security.

What is the CISA Known Exploited Vulnerabilities (KEV) Catalog?

Unlike standard CVSS-based scoring, which assesses theoretical risk, the CISA Known Exploited Vulnerabilities (KEV) Catalog focuses on vulnerabilities with confirmed active threats. The directive compels organizations to prioritize these specific CVEs, as they are actively targeted by malicious actors.

Vulnerabilities Requiring Immediate Remediation

The following six vulnerabilities are currently listed in the KEV catalog for SAP applications:

CVEImpactSAP Note
CVE-2010-5326Authentication bypass / RCE in NetWeaver AS Java1445998
CVE-2016-3976Directory traversal in AS Java2234971
CVE-2016-9563Denial of Service (DoS) in AS Java2296909
CVE-2018-2380Directory traversal in SAP CRM2547431
CVE-2020-6207Missing authentication in Solution Manager2890213
CVE-2020-6287RECON vulnerability in AS Java2934135

How to secure your SAP environment

To comply with the directive and protect your critical assets, organizations should:

  • Review and Patch: Apply the relevant SAP notes listed above to all affected systems.
  • Automate Discovery: Use the Cybersecurity Extension for SAP to automate the discovery of systems vulnerable to these specific CVEs.
  • Monitor for Exploits: Implement logging and monitoring to detect exploit signatures associated with these vulnerabilities. The Cybersecurity Extension for SAP provides mechanisms to investigate and respond to these specific threats.

Frequently Asked Questions

Why does CISA prioritize these vulnerabilities?

CISA prioritizes these vulnerabilities because they are actively exploited by threat actors. Unlike traditional scoring, the KEV catalog focuses on real-world threat intelligence, meaning these flaws are currently being used to compromise systems.

What are the risks of CVE-2020-6287 (RECON)?

The RECON vulnerability in the LM Configuration Wizard allows unauthenticated attackers to perform administrative functions, such as creating new privileged users, effectively granting them full control over the SAP Java stack.

How does the Cybersecurity Extension for SAP assist with compliance?

The Cybersecurity Extension for SAP automates the identification of vulnerable systems and monitors logs for signs of exploit attempts. It serves as a comprehensive tool for vulnerability management across SAP applications, databases, and host layers.

Share the Post: