Major SAP Vulnerability Allows Hackers to Evade Authentication and Access Systems

SAP has issued its August 2024 security update, addressing 17 newly identified vulnerabilities, including two severe issues that could let attackers bypass authentication and fully compromise affected systems.

The most critical issue, CVE-2024-41730, impacts SAP BusinessObjects Business Intelligence Platform versions 430 and 440. With a CVSS score of 9.8, this “missing authentication check” flaw allows unauthorized users to gain a logon token via a REST endpoint when Single Sign-On is enabled on Enterprise authentication. Exploitation of this vulnerability could lead to complete system compromise, affecting confidentiality, integrity, and availability.

The second major vulnerability, CVE-2024-29415, is a server-side request forgery flaw present in applications built with SAP Build Apps versions older than 4.11.130. Scoring 9.1 on the CVSS scale, this issue arises from a weakness in the ‘IP’ package for Node.js.

Additionally, SAP’s security advisory highlights four high-severity vulnerabilities:

  • CVE-2024-42374: XML injection vulnerability in SAP BEx Web Java Runtime Export Web Service (CVSS 8.2).
  • CVE-2023-30533: Prototype pollution issue in SAP S/4 HANA’s Manage Supply Protection module (CVSS 7.8).
  • CVE-2024-34688: Denial of Service vulnerability in SAP NetWeaver AS Java’s Meta Model Repository component (CVSS 7.5).
  • CVE-2024-33003: Information disclosure vulnerability in SAP Commerce Cloud (CVSS score not provided).

Given SAP’s extensive use among major corporations, these vulnerabilities represent significant threats to enterprise networks and sensitive data. SAP has provided patches to address these vulnerabilities, and immediate application of these updates is strongly recommended.

For CVE-2024-41730, patches are available for:

  • SBOP BI PLATFORM SERVERS 4.3 – Patch Level SP005
  • SBOP BI PLATFORM SERVERS 2025 – Patch Level SP00
  • SBOP BI PLATFORM SERVERS 4.3 – Patch Level SP004

As no workarounds are available, applying these patches is the only recommended mitigation strategy.

Organizations using SAP products should prioritize addressing these vulnerabilities to safeguard their critical business operations and data. Although there are no current reports of active exploits for CVE-2024-41730, it is prudent to act swiftly given the high risk and critical nature of the flaw.

More Articles & Posts