News

SAP Bug Still Exposing Companies Six Years After Being Patched!

We are constantly reminded about keeping our software up to date, from something like Word to the auto-updates of Windows 10. Amongst all the features and tweaks we often get with these updates, the first and foremost reason for fixes and updates is often security, with each update fixing another problem found in software. SAP had a rather bad bug back in 2010 before it updated its system to fix the problem. The issue now is that companies are still being caught by the vulnerability that was fixed six years ago.

The SAP function in question was found in the “invoker servlet”, giving hackers the ability to run Java applications without passwords or authentication credentials, essentially giving them a free pass to execute code without any issues. According to researchers at Onapsis, a security firm, the vulnerability is still being used to carry out attacks on over 36 different companies.

With companies involved in telecommunications or gas being affected by the breach, sensitive data, both about the company and their customers, is at risk while also giving an external source the ability to take control of their servers that process the data, opening up their systems to a whole different level of threat.

The invoker servlet was disabled by default in 2010, meaning that either the companies have decided to not update their systems since the fix or they’ve turned the servlet back on to make it run with something they use. While companies often have to be careful with updates, a simple bug fix like this could stop your entire system from communicating with the programs it needs to do its job, leaving such a big threat active on your system for so long can only be seen as a bad omen for the future.

Gareth Andrews

Disqus Comments Loading...

Recent Posts

Electronic Arts Titles Played for Over 11 Billion Hours in 2024

Electronic Arts (EA) announced today that its games were played for over 11 billion hours…

2 days ago

Just 15% of Steam Gaming Time in 2024 Was Spent on New Releases

Steam's annual end-of-year recap, Steam Replay, provides fascinating insights into gamer habits by comparing individual…

2 days ago

STALKER 2 Gets Massive 110GB Patch With 1800+ Fixes

GSC GameWorld released a major title update for STALKER 2 this seeking, bringing the game…

2 days ago

Intel Unveils Core 200H Processors Based on the Previous Raptor Lake Refresh

Without any formal announcement, Intel appears to have revealed its new Core 200H series processors…

3 days ago

Ubisoft Reportedly Developing a New Quadruple A Game

Ubisoft is not having the best of times, but despite recent flops, the company still…

3 days ago

STALKER 2: Heart of Chornobyl Update 1.1 Fixes 1,800 Issues and Revamps A-Life 2.0

If you haven’t started playing STALKER 2: Heart of Chornobyl yet, now might be the…

3 days ago