Feeds

SAP users slack, slow and backward on security

Some systems unpatched since 2005, says researcher

5 things you didn’t know about cloud backup

Cross-site scripting, failure to check credentials, directory traversal and SQL injection make up more than three-quarters of vulnerabilities in SAP environments, according to a presentation by ERPScan's Alexander Polyakov to RSAConference Asia Pacific 2013.

And the vulnerable state of the SAP world is increasingly attracting the attention of security researchers, Polyakov said, with nearly 60 percent of vulnerabilities found in 2013 turned up by outsiders.

That's troubling, he told delegates, because ERPScan is also observing a growing willingness by SAP users to open up interfaces to the Internet, either for remote workers, inter-office connections, or remote management.

As reported by SC Magazine Australia, which attended the conference, Polyakov said “If someone gets access to the SAP they can steal HR data, financial data or corporate secrets … or get access to a SCADA system.”

A successful intrusion into the SAP system could easily mean the “end of the business”, Polyakov claimed.

With a combination of Shodan and Google searchers, he told the conference he was able to identify more than 4,000 Internet-facing SAP environments.

And – whether it's because owners are lazy or updates are difficult – Polyakov said 35 percent of the systems ERPScan found were using NetWeaver 7 EHP 0, which hasn't been updated since 2005. Another 19 percent were running software that hasn't been patched since 2009, and 23 percent ran a version last updated in 2010.

The presentation slides can be found here. ®

Next gen security for virtualised datacentres

More from The Register

next story
Snowden on NSA's MonsterMind TERROR: It may trigger cyberwar
Plus: Syria's internet going down? That was a US cock-up
Who needs hackers? 'Password1' opens a third of all biz doors
GPU-powered pen test yields more bad news about defences and passwords
Microsoft: We plan to CLEAN UP this here Windows Store town
Paid-for apps that provide free downloads? Really
e-Borders fiasco: Brits stung for £224m after US IT giant sues UK govt
Defeat to Raytheon branded 'catastrophic result'
Hear ye, young cyber warriors of the realm: GCHQ wants you
Get involved, get a job and then never discuss work ever again
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
Microsoft cries UNINSTALL in the wake of Blue Screens of Death™
Cache crash causes contained choloric calamity
prev story

Whitepapers

Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Rethinking backup and recovery in the modern data center
Combining intelligence, operational analytics, and automation to enable efficient, data-driven IT organizations using the HP ABR approach.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.