Menu
SAP Hana users warned of security vulnerability

SAP Hana users warned of security vulnerability

Default encryption keys are the problem

SAP's S4/Hana at Sapphire Now 2015

SAP's S4/Hana at Sapphire Now 2015

Hard on the heels of the release of a newly updated version of SAP Hana, a security researcher has warned of a potentially serious vulnerability in the in-memory platform.

"If an attacker can exploit this vulnerability, he can get access to all encrypted data stored in an SAP Hana database," said Alexander Polyakov, CTO with ERPScan, which presented the details Thursday at the Black Hat Sessions XIII conference in the Netherlands.

Polyakov's firm specializes in testing enterprise resource planning (ERP) software from companies such as Oracle and SAP for security purposes. Last year, it had already found SAP Hana installations to be vulnerable to SQL injection attacks, he said.

More recently, "our goal was to understand if we can get access to more data and to other servers in the company," Polyakov explained.

What it found was that it was possible to get access to information such as user passwords and root keys because they were typically stored using the same default encryption key across Hana systems, giving potential hackers relatively easy access.

"The key is the same for every installation until the administrator changes it," Polyakov said. "After a couple of other penetration tests we found out that nobody was really changing this key."

The same issue exists on SAP mobile platforms, he added. Specifically, the application password stored in the configuration file was encrypted with the same default key in every installation.

At least one of the SQL injection vulnerabilities in Hana has already been patched, Polyakov said. In addition, SAP's own guidelines and security recommendations stipulate that the master key should be changed, Polyakov noted.

"Unfortunately, very few customers follow those recommendations," he said.

SAP works closely with external companies including ERPScan to ensure the security of its products, the company said in a statement.

"Our recommendation to all of our customers is to follow the advice in the SAP Hana Security Guide and change the static master keys that are issued with our products," it said.

If such problems exist in SAP's code, it's likely there's a similar issue in custom applications developed by third parties or by in-house developers "who are much less aware of secure development and can make more mistakes," Polyakov said.

It used to be common for software to use default passwords, he noted.

"Now we have a new problem: encryption keys with a default value," he said.

Eventually, Polyakov added, "vendors will give users the option to enter a security key during installation rather than putting somewhere in 160 pages of documents that the default key should be changed."


Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags applicationssecurityenterprise resource planningSAPsoftwareExploits / vulnerabilitiesData management

Featured

Slideshows

Sizing up the NZ security spectrum - Where's the channel sweet spot?

Sizing up the NZ security spectrum - Where's the channel sweet spot?

From new extortion schemes, outside threats and rising cyber attacks, the art of securing the enterprise has seldom been so complex or challenging. With distance no longer a viable defence, Kiwi businesses are fighting to stay ahead of the security curve. In total, 28 per cent of local businesses faced a cyber attack last year, with the number in New Zealand set to rise in 2017. Yet amidst the sensationalism, media headlines and ongoing high profile breaches, confusion floods the channel, as partners seek strategic methods to combat rising sophistication from attackers. In sizing up the security spectrum, this Reseller News roundtable - in association with F5 Networks, Kaspersky Lab, Tech Data, Sophos and SonicWall - assessed where the channel sweet spot is within the New Zealand channel. Photos by Maria Stefina.

Sizing up the NZ security spectrum - Where's the channel sweet spot?
Kiwi channel comes together for another round of After Hours

Kiwi channel comes together for another round of After Hours

The channel came together for another round of After Hours, with a bumper crowd of distributors, vendors and partners descending on The Jefferson in Auckland. Photos by Maria Stefina.​

Kiwi channel comes together for another round of After Hours
Consegna comes to town with AWS cloud offerings launch in Auckland

Consegna comes to town with AWS cloud offerings launch in Auckland

Emerging start-up Consegna has officially launched its cloud offerings in the New Zealand market, through a kick-off event held at Seafarers Building in Auckland.​ Founded in June 2016, the Auckland-based business is backed by AWS and supported by a global team of cloud specialists, leveraging global managed services partnerships with Rackspace locally.

Consegna comes to town with AWS cloud offerings launch in Auckland
Show Comments