SAP CRM vulnerabilities identified by ERPScan’s researchers

SAP GermanyERPScan’s researchers — at the Troopers security conference — have disclosed the details of two vulnerabilities that allow compromising SAP CRM system.

This application stores business-critical data such as clients’ personal information resulting into reputational and cost losses.

Troopers security conference is an annual event with a special track focused on SAP security.

SAP, a software company based in Germany, was not available for comments on the security threat to its CRM customers.

“It takes nothing to exploit these vulnerabilities. Perpetrators can remotely read any file in SAP CRM without authentication. We scanned the Internet and found nearly 500 SAP servers that are prone to it,” said Vahagn Vardanyan, senior security researcher of ERPScan.

ERPScan identified directory traversal and log injection vulnerabilities in the solution. The two issues in combination lead to information disclosure, privilege escalation, and complete SAP systems compromise. ERPScan said that the two bugs can wreak havoc in any company running SAP CRM.

0 0 votes
Article Rating
Baburajan Kizhakedath
Baburajan Kizhakedath
Baburajan Kizhakedath is the editor of InfotechLead.com. He has three decades of experience in tech media.
Subscribe
Notify of
0 Comments
Oldest
Newest Most Voted

Latest

More like this
Related

7 MDR Solutions for Converged IT and OT Security Operations

The most dangerous incident in a connected industrial enterprise...

AI Ransomware Costs Just $4 Per Target as Automated Attacks Raise Million-Dollar Enterprise Risks

Artificial intelligence is lowering the cost and technical barriers...

CrowdStrike Revenue Rises 26% to $1.47 Billion as AI Security Demand Lifts FY27 Forecast

CrowdStrike has raised its fiscal 2027 revenue forecast after...