Recent research confirms that attackers are actively targeting and weaponizing vulnerabilities in SAP applications. With some unprotected cloud installations being compromised in under three hours, and patches being weaponized in less than 72 hours, organizations must move beyond basic patching to implement active threat detection.
The Reality of Active SAP Exploitation
A joint report by SAP and a security research firm has provided conclusive evidence of active exploitation targeting SAP systems. The investigation identified over 300 successful compromises, characterized by attackers modifying user configurations and exfiltrating sensitive business information.
The report highlights six specific vulnerabilities (CVEs) that are frequently targeted. While SAP has released patches for these issues, many organizations remain vulnerable due to incomplete mitigation efforts.
Targeted SAP Vulnerabilities
Organizations should audit their landscapes for these six critical vulnerabilities, which are currently being actively exploited:
| CVE | SAP Security Note | Impact |
|---|---|---|
| CVE-2010-5326 | 1445998 | Authentication bypass / RCE |
| CVE-2018-2380 | 2547431 | Directory traversal |
| CVE-2016-3976 | 2234971 | Directory traversal |
| CVE-2016-9563 | 2296909 | Denial of Service |
| CVE-2020-6287 | 2934135 | Missing authentication (RECON) |
| CVE-2020-6207 | 2890213 | Missing authentication |
How to Protect Your SAP Landscape
SAP strongly recommends that customers immediately assess their systems for indicators of compromise, such as the creation of unauthorized privileged users. Beyond applying the necessary security notes, organizations should implement automated threat detection.
The Cybersecurity Extension for SAP is an SAP-certified solution that automates vulnerability management and threat detection. It goes beyond simple patching by:
- Detecting Exploit Signatures: Identifying attempts to target the CVEs listed above.
- Automated Alerting: Notifying security teams of suspected breaches in real-time.
- Guided Investigation: Providing step-by-step procedures to investigate and respond to security incidents.
Frequently Asked Questions
How fast are SAP vulnerabilities being exploited?
Research indicates that attackers are weaponizing SAP patches in less than 72 hours, and unprotected cloud-based SAP installations can be discovered and compromised in as little as three hours.
What should I look for during an SAP security assessment?
Assessments should focus on identifying indicators of compromise, such as the unauthorized creation of privileged users or unexpected configuration changes. It is also vital to audit systems connected to known vulnerable targets.
How does the Cybersecurity Extension for SAP help?
The Cybersecurity Extension for SAP automates the discovery of unpatched systems and monitors logs for specific exploit signatures. This proactive approach allows security teams to detect and respond to threats that bypass standard perimeter defenses.
