Tag: SAP

SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack
News

SAP-Related npm Packages Compromised in Credential-Stealing Supply Chain Attack

A new supply chain assault operation using malware that steals credentials is targeting SAP-related npm packages, according to cybersecurity analysts. The campaign, dubbed the "mini Shai-Hulud," has impacted the following packages connected to SAP's JavaScript and cloud application development environment, according to reports from Aikido Security, SafeDep, Socket, StepSecurity, and Google-owned Wiz: mbt@1.2.48 @cap-js/db-service@2.10.1 @cap-js/postgres@2.2.2 @cap-js/sqlite@2.2.2 According to Socket, the impacted versions added new installation-time behavior that wasn't previously included in these packages' anticipated capabilities. A preinstall script that functions as a runtime bootstrapper was added to the compromised releases. It downloads and extracts a platform-...
7 New Exploited Vulnerabilities are Added to CISA Database
Business

7 New Exploited Vulnerabilities are Added to CISA Database

Based on the evidence of active exploitation, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) decided to add a significant SAP security weakness to its list of known exploited vulnerabilities on Thursday. The problem in question, CVE-2022-22536, was fixed by SAP as part of its Patch Tuesday updates for February 2022. It carries the highest risk score of 10.0 on the CVSS vulnerability scoring system. So, without any delay let's talk about the 7 New Exploited Vulnerabilities Added to CISA Database. Described as an HTTP request smuggling vulnerability, the shortcoming impacts the following product versions - SAP Web Dispatcher (Versions - 7.49, 7.53, 7.77, 7.81, 7.85, 7.22EXT, 7.86, 7.87)SAP Content Server (Version - 7.53)SAP NetWeaver and ABAP Platform (Versions - ...