Critical Vulnerability Hits SAP Enterprise Applications
RECON could allow an unauthenticated attacker to take control of SAP enterprise applications through the web interface.
The US Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA) has issued an alert on a critical vulnerability in SAP NetWeaver AS Java. The vulnerability could allow an unauthenticated attacker to use HTTP for takeover of applications built using NetWeaver.
The vulnerability, CVE-2020-6287, involves a lack of authentication in a web component of NetWeaver AS Java. Because of the nature of the components, applications across a broad swath of business-critical enterprise SAP installations could be affected.
Dubbed "Remote Exploitable Code on Netweaver" (RECON) by the researchers at Onapsis who discovered it, the vulnerability has been given a CVSS score of 10, the most critical.
SAP has issued a patch for the vulnerability. Both SAP and CISA urge SAP customers to apply the patch immediately.
Read more here.
About the Author
You May Also Like
How to Evaluate Hybrid-Cloud Network Policies and Enhance Security
September 18, 2024DORA and PCI DSS 4.0: Scale Your Mainframe Security Strategy Among Evolving Regulations
September 26, 2024Harnessing the Power of Automation to Boost Enterprise Cybersecurity
October 3, 202410 Emerging Vulnerabilities Every Enterprise Should Know
October 30, 2024
State of AI in Cybersecurity: Beyond the Hype
October 30, 2024[Virtual Event] The Essential Guide to Cloud Management
October 17, 2024Black Hat Europe - December 9-12 - Learn More
December 10, 2024SecTor - Canada's IT Security Conference Oct 22-24 - Learn More
October 22, 2024