Rewterz

Rewterz Threat Advisory – CVE-2019-9489 Trend Micro OfficeScan XG Data Manipulation Vulnerability

April 10, 2019
Rewterz

Rewterz Threat Alert – Chase Business Themed Phishing Campaign – IoCs

April 10, 2019

Rewterz Threat Advisory – CVE-2019-0283 – SAP NetWeaver Process Integration Multiple Vulnerabilities

Severity

Medium

Analysis Summary

1) An error related to the Adapter Engine can be exploited to spoof Digital Signature.

2) An error related to the Runtime Workbench can be exploited to disclose certain information.

3) An error related to the Messaging System can be exploited to disclose certain information.

Impact

  • Exposure of sensitive information
  • Spoofing

Affected Vendors

SAP

Affected Products

  • SAP NetWeaver Process Integration 750
  • SAP NetWeaver Process Integration 740
  • SAP NetWeaver Process Integration 731
  • SAP NetWeaver Process Integration 730
  • SAP NetWeaver Process Integration 711
  • SAP NetWeaver Process Integration 710

Remediation

Apply SAP Security Note 2742758.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.