Technology newsroom
π¨ Urgent! Critical SAP Commerce Cloud Vulnerability Under Attack β Admins Must Patch Immediately!
Urgent alert! A critical remote code execution (RCE) vulnerability (CVSS 10.0) in SAP Commerce Cloud is actively being exploited. Just three days after SAP released the patch, administrators must update immediately to prevent server compromise.
π Key Highlights:
- CVE-2024-37178 is a Remote Code Execution (RCE) vulnerability that allows malicious actors to compromise servers without authentication.
- Active exploitation has been reported, just three days after SAP released a corrective patch.
- Administrators using all affected versions of SAP Commerce Cloud must update security patches as urgently as possible to prevent damage.
The situation is concerning for SAP Commerce Cloud users, as threat intelligence company Defused has revealed that a maximum severity security vulnerability, for which a patch was released only three days ago, is now being actively exploited. The vulnerability is identified as CVE-2024-37178 and has received a maximum CVSS score of 10.0.
This vulnerability is a Remote Code Execution (RCE) type, meaning attackers can successfully run malicious code remotely on SAP Commerce Cloud servers. Most concerning is that this attack requires no authentication, allowing hackers to gain complete control over the system, potentially leading to the theft of customer or financial data, or the complete disruption of e-commerce services.
π‘οΈ Recommendations and Prevention
SAP has already released a security patch to address this vulnerability. Given the rapid and widespread active exploitation, all administrators using SAP Commerce Cloud urgently need to check for and install the latest patch immediately. Negligence or delay could lead to unforeseen severe damage to businesses.
The discovery of this vulnerability originated from the security company Onapsis. However, the fact that hackers were able to reverse-engineer the patch and develop exploitation tools within just a few days highlights the speed and danger of current cyber threats. Regular security patch updates are no longer an option but a strict necessity for all organizations.
π¬ Does your organization regularly check and update security patches for SAP systems or other critical systems? Let's share your approaches.