Version Française [x_custom_headline type=”left” level=”h4″ looks_like=”h4″]Introduction[/x_custom_headline] In SAP version prior SAP Netweaver 7.40, for communication between Oracle and SAP purpose, the Oracle database is installed with the remote_os_authent parameter enable. …
Compromising SAP by exploiting the RFC Gateway
Version Française [x_custom_headline type=”none” level=”h4″ looks_like=”h4″]Introduction[/x_custom_headline] Some of SAP vulnerabilities couldn’t be ‘patched’, because they do not concern a bug in a program but a bad configuration of a service …
SAP is -also- vulnerable to injections
Version Française [x_custom_headline type=”none” level=”h4″ looks_like=”h4″]Introduction[/x_custom_headline] In July 2016, SAP has corrected a vulnerability in SAP Netweaver, every versions concerned : a SQL and Code injection, SAP Note 2311011 and …
SAP HANA : Pentest through TREXNet
Version Française [x_custom_headline type=”none” level=”h4″ looks_like=”h4″]Introduction[/x_custom_headline] In 2016 an important security vulnerability was corrected on the new SAP platform : SAP HANA. An anonymous ‘Remote command Execution’ was possible. The …