Horizon Alert
Summary of the vulnerability and why it matters
A vulnerability in SAP Supplier Relationship Management allows authenticated users to upload malicious files, potentially leading to the execution of malware and significant impacts on confidentiality, integrity, and availability.
- Uploading malicious files can lead to malware.
- It affects SAP Supplier Relationship Management technology.
- Confirm relevance and exposure to SAP systems.
Attack Path
How an attacker could exploit the issue
An attacker with existing access to SAP Supplier Relationship Management could upload a malicious file, such as an executable. If another user downloads and runs this file, it could lead to the execution of malware, potentially compromising the confidentiality, integrity, and availability of the application.
- Authenticated access required.
- User downloads and executes uploaded file.
- Malware execution and application compromise.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability in SAP Supplier Relationship Management could allow an authenticated attacker to upload arbitrary files. If a user downloads and executes these files, they might inadvertently host malware, potentially impacting the confidentiality, integrity, and availability of the application.
- Arbitrary file uploads are at risk.
- Uploaded files may be downloaded and executed.
- High impact to application confidentiality, integrity, availability.
Operational Fix
Recommended remediation, mitigation, and detection steps
SAP Supplier Relationship Management instances are likely managed by platform or application teams responsible for enterprise resource planning systems. The first step is to identify all deployed SAP SRM instances, confirm their network reachability and business criticality, and then engage the accountable SAP Basis or application owner to assess exposure and plan remediation.
- Identify SAP SRM instances and ownership.
- Verify network reachability and criticality.
- Plan remediation with SAP Basis owner.