Web Hack List

Other nomination

Chained to hit: Discovering new vectors to gain remote and root access in SAP Enterprise Software

Maps SAP's proprietary P4 protocol and reports 13 unauthenticated flaws in the JNDI services it exposes: SQL injection, arbitrary OS file read, blind SSRF with header injection and code execution in Solution Manager agent collectors, plus a JNDI reference injection in Enterprise Portal that needs no reverse connection.

Record

Researcher
Pablo Artuso and Yvan Genuer
Format
Whitepaper

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Pablo Artuso and Yvan Genuer, first published at the original source. Preserved copies are kept so the citation survives its host.