<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ERPScan Security Scanner for SAP</title>
	<atom:link href="http://erpscan.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://erpscan.com</link>
	<description>Invest in security to secure investments</description>
	<lastBuildDate>Tue, 15 May 2012 14:50:32 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>(25 May 2012) Upcoming webinar: ERPScan Security Scanner for SAP 2.0 Review</title>
		<link>http://erpscan.com/press-center/news/upcoming-webinar-4-may-2012-erpscan-security-scanner-for-sap-2-0-review/</link>
		<comments>http://erpscan.com/press-center/news/upcoming-webinar-4-may-2012-erpscan-security-scanner-for-sap-2-0-review/#comments</comments>
		<pubDate>Thu, 03 May 2012 09:30:28 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Future events]]></category>
		<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://erpscan.com/?p=2748</guid>
		<description><![CDATA[Attention! We will accept requests only from corporate emails. https://www3.gotomeeting.com/register/666896790 Today, almost all critical operations like procurements, stock resources management, human resources management, financial reports and much more, and all the data related to them, are stored in SAP system. This is why the main target for an insider or an external attacker would be to gain illicit access to SAP with the purpose of malicious manipulation of company resources. In spite of the increasing popularity of ERP systems security in the security community, companies are still vulnerable to cybercriminal and insider attacks. At this moment SAP has released more [...]]]></description>
			<content:encoded><![CDATA[Attention! We will accept requests only from corporate emails.

<a href="https://www3.gotomeeting.com/register/666896790">https://www3.gotomeeting.com/register/666896790</a>
<blockquote>Today, almost all critical operations like procurements, stock resources management, human resources management, financial reports and much more, and all the data related to them, are stored in SAP system. This is why the main target for an insider or an external attacker would be to gain illicit access to SAP with the purpose of malicious manipulation of company resources. In spite of the increasing popularity of ERP systems security in the security community, companies are still vulnerable to cybercriminal and insider attacks. At this moment SAP has released more than 2000 Security notes closing various vulnerabilities, which is quite a lot, especially if you keep in mind that sometimes it is enough to get access to all business critical data through only one issue. An example was presented at BlackHat last summer. On the other side, almost every company develops custom ABAP code which can also have vulnerabilities and backdoors left by developers - said Alexander Polyakov, CTO of ERPScan.</blockquote>
Speaker:
Alexander Polyakov
CTO ERPScan]]></content:encoded>
			<wfw:commentRss>http://erpscan.com/press-center/news/upcoming-webinar-4-may-2012-erpscan-security-scanner-for-sap-2-0-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>(6 July 2012) Upcoming Presentation At Just4meeting conference at Portugal “Top 10 SAP Vulnerabilities And Attacks By Alexander Polyakov ERPScan CTO”</title>
		<link>http://erpscan.com/press-center/future-events/6-july-2012-upcoming-presentation-at-just4meeting-conference-at-portugal-%e2%80%9ctop-10-sap-vulnerabilities-and-attacks-by-alexander-polyakov-erpscan-cto%e2%80%9d/</link>
		<comments>http://erpscan.com/press-center/future-events/6-july-2012-upcoming-presentation-at-just4meeting-conference-at-portugal-%e2%80%9ctop-10-sap-vulnerabilities-and-attacks-by-alexander-polyakov-erpscan-cto%e2%80%9d/#comments</comments>
		<pubDate>Thu, 03 May 2012 09:10:16 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Future events]]></category>

		<guid isPermaLink="false">http://erpscan.com/?p=2764</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[]]></content:encoded>
			<wfw:commentRss>http://erpscan.com/press-center/future-events/6-july-2012-upcoming-presentation-at-just4meeting-conference-at-portugal-%e2%80%9ctop-10-sap-vulnerabilities-and-attacks-by-alexander-polyakov-erpscan-cto%e2%80%9d/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>(21-26 July 2012) Upcoming Presentation At BlackHat USA “SSRF vs. Business Critical Applications” By Alexander Polyakov ERPScan CTO and Dmitry Chastuchin”</title>
		<link>http://erpscan.com/press-center/future-events/21-26-july-2012-upcoming-presentation-at-blackhat-usa-%e2%80%9cssrf-vs-business-critical-applications%e2%80%9d-by-alexander-polyakov-erpscan-cto-and-dmitry-chastuchin%e2%80%9d/</link>
		<comments>http://erpscan.com/press-center/future-events/21-26-july-2012-upcoming-presentation-at-blackhat-usa-%e2%80%9cssrf-vs-business-critical-applications%e2%80%9d-by-alexander-polyakov-erpscan-cto-and-dmitry-chastuchin%e2%80%9d/#comments</comments>
		<pubDate>Thu, 03 May 2012 09:00:01 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Future events]]></category>

		<guid isPermaLink="false">http://erpscan.com/?p=2769</guid>
		<description><![CDATA[]]></description>
			<content:encoded><![CDATA[]]></content:encoded>
			<wfw:commentRss>http://erpscan.com/press-center/future-events/21-26-july-2012-upcoming-presentation-at-blackhat-usa-%e2%80%9cssrf-vs-business-critical-applications%e2%80%9d-by-alexander-polyakov-erpscan-cto-and-dmitry-chastuchin%e2%80%9d/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ERPScan has released a new version of Security Scanner for SAP: ERPScan v2.0</title>
		<link>http://erpscan.com/press-center/news/erpscan-has-released-a-new-version-of-security-scanner-for-sap-erpscan-v2-0/</link>
		<comments>http://erpscan.com/press-center/news/erpscan-has-released-a-new-version-of-security-scanner-for-sap-erpscan-v2-0/#comments</comments>
		<pubDate>Tue, 24 Apr 2012 07:55:55 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Press Center]]></category>
		<category><![CDATA[Press Release]]></category>

		<guid isPermaLink="false">http://erpscan.com/?p=2701</guid>
		<description><![CDATA[ERPScan company, one of the key players in ERP security, has released  ERPScan Security Scanner for SAP 2.0 – a complex solution to continuously monitor all areas of SAP security, from vulnerability assessment and misconfigurations to ABAP code review and analysis of business-critical privileges. One of the most significant changes is a new module which can make static analysis of ABAP code security. It makes ERPScan the only solution on the market which makes both security assessment of platform and code review. We have also significantly increased the number of anonymous checks which can be performed in Penetration testing mode [...]]]></description>
			<content:encoded><![CDATA[<a href="http://erpscan.com/wp-content/uploads/2012/04/ERPScan-SAP-2.png"><img src="http://erpscan.com/wp-content/uploads/2012/04/ERPScan-SAP-2-300x83.png" alt="" title="ERPScan-SAP 2" width="300" height="83" class="alignnone size-medium wp-image-2709" /></a>
<br />
<div align="justify"><p>ERPScan company, one of the key players in ERP security, has released  ERPScan Security Scanner for SAP 2.0 – a complex solution to continuously monitor all areas of SAP security, from vulnerability assessment and misconfigurations to ABAP code review and analysis of business-critical privileges.</p><p>

One of the most significant changes is a new module which can make static analysis of ABAP code security. It makes ERPScan the only solution on the market which makes both security assessment of platform and code review. We have also significantly increased the number of anonymous checks which can be performed in Penetration testing mode to help companies identify issues without using credentials in the system. The new engine can help to perform audit and compliance checks not just through RFC – it allows making complete scan through the web-interface which is a great feature for external penetration tests and can make pen-testers’ lives easier.</p>


<p>
“<em>Today, almost all critical operations like procurements, stock resources management, human resources management, financial reports and much more, and all the data related to them, are stored in SAP system. This is why the main target for an insider or an external attacker would be to gain illicit access to SAP with the purpose of malicious manipulation of company resources. In spite of the increasing popularity of ERP systems security in the security community, companies are still vulnerable to cybercriminal and insider attacks. At this moment SAP has released more than 2000 Security notes closing various vulnerabilities, which is quite a lot, especially if you keep in mind that sometimes it is enough to get access to all business critical data through only one issue. An example was presented at BlackHat last summer. On the other side, almost every company develops custom ABAP code which can also have vulnerabilities and backdoors left by developers</em>”, said <strong>Alexander Polyakov</strong>, CTO of ERPScan.

</p>

<p>
Using ERPScan, all kinds of customers can decrease their expenses and get different benefits.</p><p>

<ul>
	<li>Consulting companies can save time and resources. ERPScan allows them to significantly simplify the task of assessment by automating most of the ordinary checks, so auditors can pay more attention to the analysis of the customized part. Moreover, the unique database of checks gives consulting companies competitive advantages.</li>

	<li>CISOs can effectively monitor security of SAP systems and prevent insider and hacker threats.</li>

	<li>Penetration testers can easily perform black-box and white-box assessments of SAP with the largest knowledge base in the world and 0-day vulnerabilities.</li>

	<li>SAP team can manage business-critical authorizations and control development by applying preventive measures.</li>
</ul>

</p><p>


“<em>SAP security assessment, according to our experience, usually takes quite a long time. Additionally, the complexity of the system and the large amount of different installation types require the participation of specialists from various fields of security. Even the application server may have either ABAP or Java platform, and they require completely different specialists, not to mention particular applications and modules. ERPScan allows you to significantly simplify the task of assessment by automating most of the ordinary checks, so you can pay more attention to the analysis of the customized part</em>”, said <strong>Alexander Polyakov</strong>.
</p><p>
More new functions:</p><p>

<ul>
	<li>Support of different web application types (bsp/iviews/jsp/webservices/webdynpro’s)</li>


	<li>More than 5000 different checks covering misconfigurations, vulnerabilities, access to web-applications; search for 50 different types of  vulnerabilities in ABAP code</li>


	<li>Elaborated black-box vulnerability assessment</li>

	<li>Cataloguing of SAP systems and services</li>
</ul>


</p><p>
“<em>Earlier, you needed to implement many different solutions to secure SAP from threats, now it is all in one place</em>”, said <strong>Ilya Medvedovsky</strong>, CEO of ERPScan.</p></div>]]></content:encoded>
			<wfw:commentRss>http://erpscan.com/press-center/news/erpscan-has-released-a-new-version-of-security-scanner-for-sap-erpscan-v2-0/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Installation of vendor&#8217;s patch does not always guarantee security</title>
		<link>http://erpscan.com/press-center/news/installation-of-vendors-patch-does-not-always-guarantee-security/</link>
		<comments>http://erpscan.com/press-center/news/installation-of-vendors-patch-does-not-always-guarantee-security/#comments</comments>
		<pubDate>Mon, 26 Mar 2012 10:30:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Press Center]]></category>
		<category><![CDATA[Press Release]]></category>

		<guid isPermaLink="false">http://erpscan.com/?p=2692</guid>
		<description><![CDATA[Experts from ERPScan Company, specialized in business applications security and SAP security, found out that even well-timed installation of vendor’s patch does not always guarantee security because the fixes are not always correct. In 2011, three critical patches from the key software vendors like SAP, IBM and VMware actually did not fix or not completely fixed vulnerabilities that ERPScan or other researchers had found in their products. This allows potential attackers to continue exploiting the vulnerabilities, whereas all most scanners and auditors would say that the problem is no more because patch is installed. On the BlackHat Europe conference held [...]]]></description>
			<content:encoded><![CDATA[<p>
Experts from <a href="http://www.erpscan.com">ERPScan Company</a>, specialized in business applications security and SAP security, found out that even well-timed installation of vendor’s patch does not always guarantee security because the fixes are not always correct. In 2011, three critical patches from the key software vendors like SAP, IBM and VMware actually did not fix or not completely fixed vulnerabilities that ERPScan or other researchers had found in their products. This allows potential attackers to continue exploiting the vulnerabilities, whereas all most scanners and auditors would say that the problem is no more because patch is installed.</p>
<p>On the BlackHat Europe conference held from March 14 to March 16, <b>Alexey Sintsov</b>, head of information security audit department in <a href="http://www.erpscan.com">ERPScan Company</a>, shared his experience in penetration testing and presented the results of a recently conducted <a href="http://erpscan.com/wp-content/uploads/2012/03/bh-eu-12-Sintsov-Lotus_Domino-WP.pdf">research</a> of Lotus Domino security.</p><p>
His presentation told about lack of time and frequently desire for companies to dig into the details of existing vulnerabilities to exploit them, and how it often impairs the quality of their work.</p><p>
In the demonstration, a private vulnerability in Lotus Domino was quite quickly disassembled, the resulting exploit used, the existing patch bypassed and a critical 0-day vulnerability found. The result was an attack on the Domino Controller service (the Lotus Domino administration service) which allows full server compromise.</p><p>
Vulnerable services were also exposed which, one would suppose, should not be accessible from the Internet. Moreover, in the course of the research, services with the 0-day vulnerability and ever older vulnerabilities were found on the USA government servers (the .gov domain), on the servers of Russian universities and, curiously enough, even in the corporate network of IBM itself.</p><p>
Thus, it can be concluded that penetration threats are quite easily actualized for pretty much any network; even governments and corporate giants are vulnerable to attacks from the Internet, such as those made by LulzSec and Anonymous.</p>
<p> Links to vulnerabilities:</p>
  Vulnerability in IBM Lotus (<a href="http://www.zerodayinitiative.com/advisories/ZDI-11-110/">ZDI</a>)</br>
  Vulnerability in VMware (<a href="http://dsecrg.com/pages/vul/show.php?id=342">Advisory</a>,<a href="http://www.vmware.com/security/advisories/VMSA-2011-0014.html">Vendor’s patch</a>)</br>
  Vulnerabilities in SAP (<a href="http://erpscan.com/advisories/dsecrg-11-039-sap-netweaver-th_grep-module-code-injection-vulnerability-new/">Advisory</a>,
<a href="https://service.sap.com/sap/support/notes/1580017">New patch</a>,
<a href="https://service.sap.com/sap/support/notes/1433101">Old patch</a>); another one is still being patched again.</p><p>
Alexey’s presentation can be found <a href="http://erpscan.com/wp-content/uploads/2012/03/bh-eu-12-Sintsov-Lotus_Domino-Slides.pdf">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://erpscan.com/press-center/news/installation-of-vendors-patch-does-not-always-guarantee-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Whitepaper &#8220;Lotus Domino: Penetration Through the Controller&#8221; from BlackHat Europe 2012</title>
		<link>http://erpscan.com/publications/whitepaper-lotus-domino-penetration-through-the-controller-from-blackhat-europe-2012/</link>
		<comments>http://erpscan.com/publications/whitepaper-lotus-domino-penetration-through-the-controller-from-blackhat-europe-2012/#comments</comments>
		<pubDate>Mon, 26 Mar 2012 10:20:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Publications]]></category>

		<guid isPermaLink="false">http://erpscan.com/?p=2689</guid>
		<description><![CDATA[On the BlackHat Europe conference held from March 14 to March 16, Alexey Sintsov, head of information security audit department in ERPScan Company, shared his experience in penetration testing and presented the results of a recently conducted research of Lotus Domino security. His presentation told about lack of time and frequently desire for companies to dig into the details of existing vulnerabilities to exploit them, and how it often impairs the quality of their work. In the demonstration, a private vulnerability in Lotus Domino was quite quickly disassembled, the resulting exploit used, the existing patch bypassed and a critical 0-day [...]]]></description>
			<content:encoded><![CDATA[<p>On the BlackHat Europe conference held from March 14 to March 16, Alexey Sintsov, head of information security audit department in ERPScan Company, shared his experience in penetration testing and presented the results of a recently conducted research of Lotus Domino security.</p><p>
His presentation told about lack of time and frequently desire for companies to dig into the details of existing vulnerabilities to exploit them, and how it often impairs the quality of their work.</p><p>
In the demonstration, a private vulnerability in Lotus Domino was quite quickly disassembled, the resulting exploit used, the existing patch bypassed and a critical 0-day vulnerability found. The result was an attack on the Domino Controller service (the Lotus Domino administration service) which allows full server compromise.</p><p>

<a href="http://erpscan.com/wp-content/uploads/2012/03/bh-eu-12-Sintsov-Lotus_Domino-WP.pdf">Whitepaper "Lotus Domino: Penetration Through the Controller", BlackHat Europe 2012</a></p>]]></content:encoded>
			<wfw:commentRss>http://erpscan.com/publications/whitepaper-lotus-domino-penetration-through-the-controller-from-blackhat-europe-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Presentation &#8220;Lotus Domino: Penetration Through the Controller&#8221; from BlackHat Europe 2012</title>
		<link>http://erpscan.com/presentations/presentation-lotus-domino-penetration-through-the-controller-from-blackhat-europe-2012/</link>
		<comments>http://erpscan.com/presentations/presentation-lotus-domino-penetration-through-the-controller-from-blackhat-europe-2012/#comments</comments>
		<pubDate>Mon, 26 Mar 2012 10:18:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Presentations]]></category>

		<guid isPermaLink="false">http://erpscan.com/?p=2683</guid>
		<description><![CDATA[On the BlackHat Europe conference held from March 14 to March 16, Alexey Sintsov, head of information security audit department in ERPScan Company, shared his experience in penetration testing and presented the results of a recently conducted research of Lotus Domino security. His presentation told about lack of time and frequently desire for companies to dig into the details of existing vulnerabilities to exploit them, and how it often impairs the quality of their work. In the demonstration, a private vulnerability in Lotus Domino was quite quickly disassembled, the resulting exploit used, the existing patch bypassed and a critical 0-day [...]]]></description>
			<content:encoded><![CDATA[<p>On the BlackHat Europe conference held from March 14 to March 16, Alexey Sintsov, head of information security audit department in ERPScan Company, shared his experience in penetration testing and presented the results of a recently conducted research of Lotus Domino security.</p><p>
His presentation told about lack of time and frequently desire for companies to dig into the details of existing vulnerabilities to exploit them, and how it often impairs the quality of their work.</p><p>
In the demonstration, a private vulnerability in Lotus Domino was quite quickly disassembled, the resulting exploit used, the existing patch bypassed and a critical 0-day vulnerability found. The result was an attack on the Domino Controller service (the Lotus Domino administration service) which allows full server compromise.</p><p>

<a href="http://erpscan.com/wp-content/uploads/2012/03/bh-eu-12-Sintsov-Lotus_Domino-Slides.pdf">"Lotus Domino: Penetration Through the Controller", BlackHat Europe 2012</a></p>]]></content:encoded>
			<wfw:commentRss>http://erpscan.com/presentations/presentation-lotus-domino-penetration-through-the-controller-from-blackhat-europe-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAP security updates in March and missing authorization vulnerabilities</title>
		<link>http://erpscan.com/press-center/sap-security-updates-in-march-and-missing-authorization-vulnerabilities/</link>
		<comments>http://erpscan.com/press-center/sap-security-updates-in-march-and-missing-authorization-vulnerabilities/#comments</comments>
		<pubDate>Thu, 22 Mar 2012 17:11:44 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[blog]]></category>
		<category><![CDATA[Press Center]]></category>
		<category><![CDATA[patch]]></category>

		<guid isPermaLink="false">http://erpscan.com/?p=2679</guid>
		<description><![CDATA[SAP has released monthly critical patch update for March 2012. This patch update closes many vulnerabilities in SAP products. Overall, more than 40 vulnerabilities were fixed, including 7 found by third-party researchers. Also, this month, 2 vulnerabilities found by ERPScan researchers Dmitriy Chastukhin and Alexey Tyurin were closed. I would like to tell you more about the corrected vulnerabilities and the risks that they involve. 1. (1607850) SAP BW – critical information disclosure. No details are available. Criticality, according to CVSS, is 7.5. 2. (1580244) SAP BASIS – missing authorization check in an RFC function. Criticality, according to CVSS, is [...]]]></description>
			<content:encoded><![CDATA[<div align="justify"><p><a href="http://www.sap.com">SAP</a> has released <strong>monthly critical patch update for March 2012</strong>. This patch update closes many vulnerabilities in SAP products. Overall, more than 40 vulnerabilities were fixed, including 7 found by third-party researchers. Also, this month, 2 vulnerabilities found by ERPScan researchers Dmitriy Chastukhin and Alexey Tyurin were closed.</p><p>
I would like to tell you <strong>more about the corrected vulnerabilities</strong> and the risks that they involve.</p><p>
1.	<u>(1607850) SAP BW</u> – critical information disclosure. No details are available. Criticality, according to CVSS, is 7.5.</br>
2.	<u>(1580244)  SAP BASIS</u>  – missing authorization check in an RFC function. Criticality, according to CVSS, is 3.5.</br>
3.	<u>(1656549)  SAP Portal</u>  –  XSS vulnerability. An attacker can use the XSS vulnerability by sending a link to malicious script to an unaware user via an e-mail, messaging or social networks. Thus, an attacker can gain access to user session and gain control over business-critical information which can be accessed by victim. Criticality, according to CVSS, is 4.3.</br>
4.	<u>(1657891) SAP BASIS</u>  – missing authorization checks in RFC function. Criticality, according to CVSS, is 2.3. An attacker can execute vulnerable transaction, program or RFC function remotely without authentication because authorization check is missing. It can lead to different threats from information disclosure to full system compromise.</br>
5.	<u>(1591427) SAP BASIS</u> – XSS vulnerability. Criticality, according to CVSS, is 4.3.</br>
6.	<u>(1658947) SAP Portal</u> – information disclosure. Criticality, according to CVSS, is 4.0.</br>
7.	<u>(1600755) SAP HR</u> – ABAP code injection through missing input validity checks. Criticality, according to CVSS, is 6.0. </br></p><p>
Today I will tell you about one of the most popular vulnerabilities, namely the <b>missing authorization checks in RFC functions</b>.</p><p>
Overall, it is one of the most popular and most easily understandable types of vulnerabilities. Think about some RFC function which fulfills some critical action in the system; call it, for example, Z_RFCEXPLOIT  (actually, the same applies to reports and transactions). The vulnerability is in the missing user authorization check (AUTHORITY-CHECK) in its code. In practice, it means that the Z_RFCEXPLOIT  function can be called by any user, provided that he or she has sufficient privileges to call RFC functions at all.</p><p>
There are 3 basic ways to call an RFC function.</p><p>
1.	<u>In the dialog mode, using the SE37 transaction.</u></br>
Privileged users usually have the rights for this kind of transaction though exceptions certainly exist.</p><p>
2.	<u>Through remote call by RFC protocol</u></br>
In this case, apart from authorization check for RFC function per se, system also checks that user has the right to access the RFC functions group (S_RFC authorization, FUGR field). This mitigates the risk of attack, but the risk remains in the case of high privileged accounts with default passwords, like SAP*, DDIC, EARLYWATCH, TMSADM or SAPCPIC.</br> 
It is notable that the last two accounts are found in % 95 of the systems we analyze, so the chances of attack are pretty high.</p><p>
3.	<u>Though remote call by WEBRFC</u></br>
It is commonly known that RFC commands can be called remotely through web interface located on the web port of SAP NetWeaver ABAP application server (relative address: /sap/bc/soap/rfc). What is specific about this method is that, first, in many organizations web interface is accessible through the Internet, and second, group authorization is not checked when calling an RFC function through this interface, which allows any user to make vulnerable RFC calls.</p><p>
Thus, vulnerabilities connected with missing authorization should not be underestimated because they are easily exploited and do not require special privileges in the system. Taking into account that there are about 2 million RFC functions in SAP, such vulnerabilities will constantly reappear in SAP products, as well as in self-developed code whose security should be thoroughly cared about.</p><p>
PS: According to ERPScan’s agreement with SAP we do not publish details of vulnerabilities until 3 months since update is released to give organizations time to install the patch.</p></div>
]]></content:encoded>
			<wfw:commentRss>http://erpscan.com/press-center/sap-security-updates-in-march-and-missing-authorization-vulnerabilities/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Upcoming webinar (29 March): ERPScan Security Scanner for SAP Review</title>
		<link>http://erpscan.com/press-center/news/upcoming-webinar-29-march-erpscan-security-scanner-for-sap-review/</link>
		<comments>http://erpscan.com/press-center/news/upcoming-webinar-29-march-erpscan-security-scanner-for-sap-review/#comments</comments>
		<pubDate>Tue, 20 Mar 2012 19:36:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>

		<guid isPermaLink="false">http://erpscan.com/?p=2675</guid>
		<description><![CDATA[For those who missed our previous webinar we will repeat it. Please keep in mind that we will register users only from corporate email. ERP systems are the core of every enterprise. ERP systems contain all of the critical business processes running inside from purchasing, payment and shipping, human resource management, production, and financial planning. All the data stored in ERP systems is of a paramount importance and any illegal access can lead to losses or even business shutdown. In order to protect your business we strongly suggest an automated system to assess component security. In this webinar you will [...]]]></description>
			<content:encoded><![CDATA[<img alt="" src="http://erpscan.com/wp-content/uploads/2012/03/erpscan.jpg" class="aligncenter" width="576" height="231" /><br /><br />


<strong>For those who missed our previous webinar we will repeat it.
Please keep in mind that we will register users only from corporate email.</strong>

<br /><br />
ERP systems are the core of every enterprise. ERP systems contain all of the critical business processes running inside from purchasing, payment and shipping, human resource management, production, and financial planning. All the data stored in ERP systems is of a paramount importance and any illegal access can lead to losses or even business shutdown. In order to protect your business we strongly suggest an automated system to assess component security. In this webinar you will learn what kind of threats target SAP systems and how our products will keep you and your data secure.

<blockquote><em>ERPScan Security Scanner for SAP is an innovative product for integrated assessment of SAP platform security and standard compliance. The system enables conducting complex security assessments while scanning SAP servers for software vulnerabilities, misconfigurations, critical access, and also performs assessment for compliance to current standards and best practices including SAP best practices and ISACA guidelines.</em></blockquote>

<a title="Register here" href="https://www3.gotomeeting.com/register/664146350">Register here</a><br />

Panelist:   Alexander Polyakov - CTO of ERPScan<br />

When:   Thursday, March 29, 2012   3:00 PM - 4:00 PM GMT<br />]]></content:encoded>
			<wfw:commentRss>http://erpscan.com/press-center/news/upcoming-webinar-29-march-erpscan-security-scanner-for-sap-review/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SAP critical patch update March 2012</title>
		<link>http://erpscan.com/press-center/news/sap-critical-patch-update-march-2012/</link>
		<comments>http://erpscan.com/press-center/news/sap-critical-patch-update-march-2012/#comments</comments>
		<pubDate>Tue, 20 Mar 2012 11:17:47 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[News]]></category>
		<category><![CDATA[Press Center]]></category>
		<category><![CDATA[Press Release]]></category>

		<guid isPermaLink="false">http://erpscan.com/?p=2669</guid>
		<description><![CDATA[SAP has released monthly critical patch update for March 2012. This patch update closes many vulnerabilities in SAP products. This month, 2 vulnerabilities found by ERPScan researchers Dmitriy Chastukhin and Alexey Tyurin were closed. Detailed list of corrected vulnerabilities is below: An XSS vulnerability was found in SAP Portal. An attacker can use the XSS vulnerability by sending a link to malicious script to an unaware user via an e-mail, messaging or social networks. Thus, an attacker can gain access to user session and gain control over business-critical information which can be accessed by victim. Update is available in SAP [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.sap.com/">SAP</a> has released monthly critical patch update for March 2012. This patch update closes many vulnerabilities in SAP products. This month, 2 vulnerabilities found by <a href="http://www.dsecrg.com/">ERPScan</a>  researchers Dmitriy Chastukhin and Alexey Tyurin were closed.</p>

<p>Detailed list of corrected vulnerabilities is below:</p>
<ul>
<li> An XSS vulnerability was found in SAP Portal. An attacker can use the XSS vulnerability by sending a link to malicious script to an unaware user via an e-mail, messaging or social networks. Thus, an attacker can gain access to user session and gain control over business-critical information which can be accessed by victim. Update is available in SAP Note 1656549. Criticality, according to CVSS, is 4.3.</li>

<li> Missing authorization checks in RFC function from BASIS module. Update is available in SAP Note 1657891. Criticality, according to CVSS, is 2.3. An attacker can execute vulnerable transaction, program or RFC function remotely without authentication because authorization check is missing. It can lead to different threats from information disclosure to full system compromise.</li></ul>

<p>SAP has traditionally published acknowledgements for found vulnerabilities to security researchers from DSecRG on their <a href="http://scn.sap.com/docs/DOC-8218">  acknowledgement page</a>.</p>
 
<p>It is highly recommended to patch all those issues to prevent business risks.</p>


<p>Advisories for those issues with technical details will be available within 3 months on <a href="http://www.erpscan.com/">ERPScan.com</a> and also on <a href="http://www.dsecrg.com/">DSecRG.com</a>.</p>

Exploits will be available soon in ERPScan Security Scanner and ERPScan SaaS.

 ]]></content:encoded>
			<wfw:commentRss>http://erpscan.com/press-center/news/sap-critical-patch-update-march-2012/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

