Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Details of Serious SAP Adaptive Server Enterprise Vulnerabilities Disclosed

Cybersecurity firm Trustwave on Wednesday disclosed the details of several vulnerabilities found by its researchers in SAP Adaptive Server Enterprise (ASE).

Cybersecurity firm Trustwave on Wednesday disclosed the details of several vulnerabilities found by its researchers in SAP Adaptive Server Enterprise (ASE).

SAP ASE is a relational database management system that is used by many major organizations, particularly in the financial sector. At one point, SAP said this product was used by a vast majority of the world’s top 25 banks.

Researchers at Trustwave analyzed SAP ASE and discovered a total of six vulnerabilities, most of which have been assigned a critical or high severity rating. The company says the security holes can allow unprivileged attackers to gain complete control of the database and possibly even the underlying operating system.

The critical issues can allow an attacker with limited privileges to execute arbitrary code with higher permissions — LocalSystem permissions on Windows systems. The flaws, tracked as CVE-2020-6248 and CVE-2020-6252, are related to the Backup Server and Cockpit components.

There is also a high-severity flaw related to the XP Server component that can also be exploited for arbitrary code execution with LocalSystem privileges, Trustwave revealed in a blog post.

Two other high-severity vulnerabilities allow privilege escalation via SQL injection attacks. The last issue, rated medium severity, affects only Linux/UNIX systems and it’s related to the presence of cleartext passwords in installation logs. This weakness can be dangerous when combined with other vulnerabilities as it can result in SAP ASE getting completely compromised.

Advertisement. Scroll to continue reading.

Trustwave reported its findings to SAP, which released patches in late April for ASE 15.7 and 16.0. SAP mentioned the vulnerabilities in the advisory it released for its May 2020 security updates.

“Organizations often store their most critical data in databases, which, in turn, are often necessarily exposed in untrusted or publicly exposed environments,” Trustwave said. “This makes vulnerabilities like these essential to address and test quickly since they not only threaten the data in the database but potentially the full host that it is running on.”

SAP’s latest round of security updates addressed 18 vulnerabilities affecting ABAP Application Server, Business Client, Business Objects, Enterprise Threat Detection, Master Data Governance, NetWeaver, and Identity Management.

Related: SAP Alerts Customers of Vulnerabilities in Cloud Products

Related: SAP’s April 2020 Security Updates Patch Five Critical Vulnerabilities

Related: Critical Vulnerabilities in SAP Solution Manager Expose Companies to Attacks

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Vensure Employer Solutions appointed Michael Lockhart as Chief Information Security Officer.

WISeKey has appointed Alexander Hirsch as Group Chief Marketing Officer.

UltraViolet Cyber has named Andrew Park Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.