Slashdot Mirror


Vulnerable SAP Deployments Make Prime Attack Targets

wiredmikey writes "Using a combination of TCP scans and Google, security researchers found that nearly a quarter of the organizations running vulnerable versions of SAP are tempting fate by leaving them exposed to the Internet. This discovery, researchers from ERPScan say, dispels the myth that SAP systems are only available from the internal network, leading to the misconception that they are protected by design. By March 2012, there were more than 2,000 security advisories published by SAP. Of those, about 7% (124) have publicly available PoC (proof-of-concept) exploit code available to the public. Many of the issues discovered are related to poor configuration or poor deployment planning. For example, 212 SAP Routers were found in Germany, which were created mainly to route access to internal SAP systems. Another issue with the vulnerable and exposed SAP installations is that many of them run on Windows NT, creating a twin set of risks for the organization, as they have to contend with a bad SAP deployment and unsupported OS that is full of security issues all by itself."

2 of 72 comments (clear)

  1. Re:Bad by Amouth · · Score: 3, Informative

    There is so much truth to that it's scary..

    --
    '...if only "Jumping to a Conclusion" was an event in the Olympics.'
  2. SAP is horrible by Mabhatter · · Score: 4, Informative

    All the pieces and parts are hard enough to keep running on a good day. Thing takes weekly downtime just to cycle modules....even simple patches shut your business users out for hours. Upgrading your version and OS shuts your business down for a week just to properly test. Sure you can use Dev boxes an HA, but you have to have ALL the users PROVE IT WORKS. So you waste terrible amounts of their TIME the could be selling stuff!!

    And of course, SAP doesn't INSTALL anything THEMSELVES. You have to use some fly-by-night third party. So just like Microsoft, it's YOUR fault when you didn't include hiring an extra $1m per year in employees to run the thing and use all the "secret settings" after they all leave you.