Rewterz

Rewterz Threat Advisory – Multiple SAP Host Agent and NetWeaver and ABAP Platform Vulnerabilities

May 12, 2022
Rewterz

Rewterz Threat Advisory – SAP BusinessObjects Enterprise Vulnerability

May 12, 2022

Rewterz Threat Advisory – SAP Employee Self Service Vulnerability

Severity

Medium

Analysis Summary

CVE-2022-29613

SAP Employee Self Service could allow a remote authenticated attacker to obtain sensitive information, caused by improper input validation. By gaining access to the Sysmon event logs, an attacker could exploit this vulnerability to obtain personal information of other users, and use this information to launch further attacks against the affected system.

Impact

  • Information Disclosure

Indicators Of Compromise

CVE

  • CVE-2022-29613

Affected Vendors

SAP

Affected Products

  • SAP Employee Self Service 605

Remediation

Current SAP customers should refer to SAP note for patch information, available from the SAP Web site (login required).
SAP Website

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.