Home > SAP software/management News > Customers warned of critical SAP flaw
SAP software/management News:
EMAIL THIS

Customers warned of critical SAP flaw

By Robert Westervelt, News Editor
26 Jul 2005 | SearchSAP.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

A critical flaw in SAP's Internet Graphics Server opens up SAP systems to remote hackers who can gain user privileges and access sensitive SAP files.
Once hacked, you can get a hold of any file on the file system.
Martin O'Neal,
security consultant, Corsaire Ltd.

Martin O'Neal, a security consultant and director at U.K.-based security firm Corsaire Ltd, discovered the vulnerability during a routine assessment of a new SAP installation for a client.

O'Neal described the flaw as critical and said it is likely in every live installation of SAP. The flaw was discovered on the Unix platform, but can be likely used to gain access on other platforms as well, O'Neal said.

"Once hacked, you can get a hold of any file on the file system," O'Neal said, in an interview with SearchSAP.com. "It's indicative of development issues -- the failure to understand fundamental problems with designing and building a Web server."

SAP released an advisory to customers urging them to upgrade the server to version 6.40, patch 11 or higher versions. ((Content component not found.))

O'Neal said there are two workarounds. If a company needs a Web-based interface, it should conduct a server upgrade, he said. An enterprise can also disable the HTTP interface, which results in eliminating the flaw, he said.

The SAP Internet Graphics Server is used in conjunction with SAP R/3 software and renders graphics to a device-dependent format. It works in conjunction with SAP Business Warehouse queries to make interactive charts and reports using Web services to integrate with a variety of third-party products.

The flaw was discovered in March, and SAP has remained tight-lipped over the issue, refusing to speak with Corsaire or share information on a fix with the security firm, O'Neal said.
Security news:

Web services security getting greater scrutiny

Visit our security topic center

"We don't know the results of their investigations or if their fix remedies the problem," O'Neal said. "When asked to see copy of their advisory SAP sent to their own clients, they said we couldn't see it."

SAP spokesman Bill Wohl said SAP conducted a review process and wanted to wait until final testing was completed on the test before making contact with Corsaire.

"We have just completed the last step in our process, which is to test the patch and make sure that it solves the issue," Wohl said. "It was only until testing was complete that we feel comfortable going back to the security service that discovered the issue."

Wohl also said the vulnerability allows initial access to the data of configuration of the operating system upon which the SAP Internet Graphics Server is based. Actual R/3 data is not exposed, Wohl said. Very few SAP customers use the Internet Graphics Server, he said.

Whol said SAP security bulletins to customers remain confidential to further protect SAP systems from attack. Details on the vulnerability are described in the SAP Note 862169.

Tags: SAP security administrationSAP and enterprise service oriented architectureVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
SAP security administration
SAP TechEd 2009 Phoenix: SearchSAP.com Special Report
How to stop SAP users from displaying SAP HR tables content
Locating user email addresses in SAP SU01 transaction code
How to map multiple SAP roles and profiles
Viewing SAP transaction codes and profiles
Managing SAP user access and password expirations
Can SAP developer include authority check for S_TCODE in a called transaction?
Cisco and SAP integrate technologies to create data privacy application
SAP administration information for a Basis interview
Transferring R/3 Admin skills to SAP NetWeaver

SAP and enterprise service oriented architecture
In an upgrade to SAP ECC 6.0, when do integrated apps get upgraded?
NetWeaver PI 7.1 easier to implement than earlier versions, SAP says
Resolving app server connectivity problems for remote users
Bucking the economic trend, HSBC embarks on NetWeaver PI project
SAP NetWeaver training tutorial
SAP NetWeaver Implementation
Learning More About SAP NetWeaver
SAP NetWeaver Configuration and Customization
Baylor College of Medicine goes wireless with NetWeaver Mobile 7.1
SOA-backed spell check wins SAP Demo Jam

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Enterprise Services Architecture  (SearchSAP.com)
NetWeaver  (SearchSAP.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



SAP Training & Employment
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
SearchSAP.com is a search service provided by TechTarget and is completely
independent of and not affiliated with SAP AG.
  TechTarget - The IT Media ROI Experts