Hello everyone, thanks for joining today’s first briefing from our Onaphy’s research lab. My name is Cecilia Diaz and I’ll be managing today’s session. Before we get started, I have some housekeeping notes. First, I want to point out the questions module within the ON24 platform. We welcome you to answer your questions at any point during the presentation and if time allows, we will answer whatever questions you can at the end of the session. You can always adjust the size of the media player and slides on your end to make them bigger or smaller depending on your preference. Now I’m going to pass it over to our presenter. With us today, we have Sethi, the Chief Technology officer and head of the Onassis Research Lab. He will be taking us through the stress briefing around a new family of vulnerabilities and health security recommendations for your team. Take it away, Sophie. Awesome. Thanks, Cecil. Hello, everyone. Thank you for joining us on this, threat briefing. I’m gonna be covering a couple of topics, but as as Cecil mentioned, I’m one of the founders of and also responsible for the Anapsis Research Labs, so that’s why I’m I’m doing this briefing. And in terms of background, I’ve been working on on cybersecurity for the past, more than fifteen years, actually more, and doing benches, mobility research and working very, very closely with vendors of ERP applications to to improve the security of those applications. So today, we are here to cover a couple of vulnerabilities and how these vulnerabilities are interconnected or related and why you should be paying attention to them. We’re gonna cover some of the patches that SAP has been releasing and the ones that were released a week ago today, on the latest patch Tuesday. Finally, we’re gonna be covering some recommendations with what you should be doing and, and also going through the support that, OnAbsys customers have had, for the past couple of weeks on through the platform and through the content that we continuously deliver. So, as a matter of as a form of introduction, I would like to start with two key topics, or two key points. Basically, as you may be familiar, the Onapsis Research Labs is a team of security researchers with a strong background on cybersecurity, security research, also, ERP applications. So they are continuously analyzing, components supporting business applications. These technology components that are interrelated, interfacing between different products. As you know, when when you deploy business applications, it’s typically, multiple pieces of of technology that are interconnected, and and the complexity of this technology, is is important because in that complexity, if customers don’t properly address that, there there could be a lot of risk. So these, researchers are continuously running research projects and reporting to SAP and Oracle mainly, but, to to the vendors, security vulnerabilities. And that leads to patches that are released either second Tuesday or third month, a week ago, for example, or quarterly by Oracle. And those patches eventually become improvements to the security of business applications. So just to give you a couple of numbers, last year, the Onapsis Research Labs crossed the a thousand zero days reported to, ERP vendors. So that’s that’s a significant improvement. A lot of those were really critical vulnerabilities and got a lot of attention. And resulting from this, all SAP customers have the ability to have more secure applications and run more secure applications. So this is one of those initiatives we are locked in terms of the the objectives and the, yeah, the goals, what we are trying to achieve, which is having more secure SAP customers in the end. So everyone would benefit from the continuous work that the Onapsis Research Labs is doing. And the other point that I wanted to make is also this comes through a tight collaboration with SAP in this case, with the product security response team, where the Unisys Research Labs provides all the information, all the technicalities on how to, detect the vulnerability, how to, exploit the vulnerability, the different ways that attackers could leverage to exploit. So whenever there’s a a patch released, this patch is covering, all the angles possible. Right? So that tight collaboration is always working very well. We, in some cases, even test the patches before those patches are available. So, with this, really, the result is more secure customers, more security for everyone through the continuous collaboration of the Synopsys Research Labs with the SAP Prog Security Response Team. So a week ago, as I mentioned, it was patched Tuesday, April eleventh. So SAP released twenty one secondurity patches. If we consider the ones released end of May sorry, end of March, we are talking about twenty four secondurity patches that the security teams at organizations had to be addressing. Out of these security patches, seven patches are directly, the outcome of eight vulnerabilities that the Anapsis Research Labs reported. I think at, at this point, on May May on April, so month four, we are we have reported to SAP multiple vulnerabilities where thirty six or thirty seven of them have been already patched. So thirty six or thirty seven vulnerabilities that have been addressed by SAP are the direct contribution of the synopsis research labs only in twenty twenty three. So that’s that’s really another way of looking at it on on this tight collaboration and and contribution to all customers. Two hot news have been issued, by the by the contribution of the analysis research labs and one CBS system. That’s as bad as it can get. Right? That is a critical vulnerability. So, hopefully, through your existing processes, you started addressing those vulnerabilities, also focusing on the CVSS ten vulnerability. But today, I’m not gonna talk about, all the vulnerabilities that were patched by SAP last week. I’m gonna be covering a couple of vulnerabilities, a set of vulnerabilities that are all interconnected. Some of them have been patched before April patch Tuesday, and one of them has been released on this latest patch Tuesday. So this group of vulnerabilities was called p four chains. This name was selected by the Anapsis Research Labs to identify a group of vulnerabilities that share some things in common. As you might guess, the before part of the name is also part of the the things that are in common. The first group of vulnerabilities that I’m gonna be covering today is these are these seven vulnerabilities. All of these, as you can see on the title, have the commonality of affecting a p four service. So what is a p four service? Well, p four is a proprietary protocol developed and released by SAP and maintained by SAP in their SAP NetWear Java stack. So they think about this as SAP solution manager has Java. SAP Enterprise Portal has Java. SAP PIPO has Java. And, many other solutions delivered by SAP also are built on top of the SAP NetWear and SAP NetWear Java systems. So these vulnerabilities affect this p four service. This p four service is, typically not Internet facing. So it’s a protocol that is used to interconnect different applications. We reported these vulnerabilities on November twenty twenty two. It was a strong collaboration as usual between Onapsis and SAP. Seven patches have been released already between December patch Tuesday and March patch Tuesday. So, hopefully, at this point, you have all those patches already applied. Depending on how you took the criticality of those, how you analyze what’s the patching cadence, the patching window you have, you may or may not have patched this, but it’s possible. Right? Because for some of these, a couple of months went by. And there is, yeah, really a variety of CVSS. Right? We have very critical vulnerabilities with nine point nine all the way to medium vulnerabilities in in the information disclosure side of things. So it’s a mix. And depending on on your patching cadence, you may or may not have applied this. But through a patch that was released by SAP last week, the risk of these vulnerabilities is elevated because of a couple of aspects that I’m gonna be covering on this presentation. So if we look at the previous group of, vulnerabilities that were patched between December and March, those vulnerabilities, the exploitation or or an attacker abusing of those vulnerabilities is limited to local network. Why? Because even though this is remotely exploitable through the p four protocol, expectation is that that protocol is typically not exposed to end users, not exposed to an untrusted networks like like the Internet, ideally restricted in the local network. Best case scenario, it’s restricted to the only the servers connecting through before, but it may be the case that it’s open to to the local network. So, it is restricted in in a way, depending on how you deploy those systems. And the impact of someone being able to exploit that unauthenticated vulnerability is basically someone being able to abuse to to sorry, extract passwords from the system, access arbitrary information from the system database, make the system render the system unusable, basically abuse of the system’s availability, performing denial of service, all the way to execute OS commands depending on on different scenarios. So these vulnerabilities could be abused in that way, always limited to local networks. However, because of a patch that was released by SAP, last week, these vulnerabilities have a higher level of importance now. Why? Because this vulnerability that affects the SAP enterprise portal can be combined and chained with the other vulnerabilities, ultimately making this initial group of vulnerabilities Internet exploitable. And by Internet exploitable, I mean exploitable through the HTTP protocol. Now if you look at this vulnerability, on itself in isolation without considering any other topic or or any other interrelation with other vulnerabilities, this vulnerability has a CVSS of six point five, which is correct. It’s correctly calculated. Right? Because CVSS analyzes the vulnerabilities individually. And if you consider the confidentiality, the integrity, the variability, and all the other aspects that CVSS version three is putting into the the equation, it is landing into a medium risk vulnerability. But if we combine this vulnerability with the other set of vulnerabilities, now we have a way more critical set of vulnerabilities because now the impact that could before be achieved through only local network now is possible to be achieved through HTTP and potentially systems that are Internet facing. This vulnerability affects SAP enterprise product, as I mentioned, and this product is, typically Internet facing because you want to expose that product to customers, vendors, partners, employees, depending on on the business processes that are integrated through SAP Enterprise product, you may be, most likely exposing it to networks that you don’t control and to users that you you don’t control as internal users, internal networks, internal computers. That’s why CVE twenty twenty three, true a seven six one is is important, and it it becomes critical, right, because this is enabling another set of vulnerabilities to be more more critical and Internet exploited. This type of combination of vulnerabilities, while it’s harder to see automation around that, is very, very it’s something that threat actors are looking for, becoming a favorite to sophisticated threat actors because they can use them to, achieve persistency on systems, where other vulnerabilities that are not critical, are more automated and used by broadly by threat actors. So, it’s important to take a look at these CVSS, this vulnerability, and address them and make sure that also you have the other vulnerabilities patched as well. So to make it visible to you, it’s this is a graph showing basically attackers trying to abuse of these p four vulnerabilities, directly, for example, from the Internet, whereas that port is typically blocked, in the the p four service or the p four TCP port is, by default five x x zero four, where x x is the instance number. This could be, let’s say, in an instance zero five thousand fifty thousand four. That port will not be exposed to Internet, and and that request will be denied. However, if we are talking about, for example, an SAP enterprise portal, someone trying to access the system through HTTP would be able to connect. That TCP port would be exposed, let’s say, through a dispatcher or, another type of load balancer or any other type of, security infrastructure that is in place that would allow the connections, the incoming connections come through the portal. So now if you think about the p four chains vulnerabilities, an attacker would be able to tunnel p four requests through HTTP and effectively being able to access the system, and eventually access data in the database, passwords, information from the secure store, arbitrary OS files, password hashes, and many other things, even render the system unusable. So all of that because of this combination of vulnerabilities, named p four chains. So what should you do in terms of addressing these vulnerabilities? Well, there are a couple of things that you can and should do. I’m gonna cover a couple of those. So first and foremost, this group of patches have elevated importance because of the the the ability for attackers to combine them. So we’re talking about a CVSS six point five in enterprise portal. We’re talking about a set of patches that were already released by SAP, some some some a couple of weeks ago, some a couple of months ago. Now if we see all of that together, it becomes very critical because it’s something that could be Internet exploitable and and could be, used to compromise those systems. So all in all, prioritize these patches, analyze, and prioritize a patch window to deploy them. Hopefully, you have done, that, but if not, it’s a a good mechanism to go back to your basis team and make sure that those vulnerabilities have been patched. Also, understand your exposure in terms of SAP enterprise portal. This latest CVSX six six point five vulnerability, is affecting the SAP enterprise portal. So make sure you prioritize that too on SAP enterprise portal, especially those that are Internet facing or exposed to networks that you don’t control, exposed to untrusted networks. There is, also, if you patch the SAP enterprise portal, make sure that the service p four over HTTP is disabled, at least until all the p four service vulnerabilities are applied. The the patches are are applied and and those vulnerabilities are not no longer there. As usual, it’s important to monitor systems. It’s important to monitor SAP enterprise portal specifically, but also other SAP, NetWire Java systems, understand if those systems are being exploited or not, understand, connections and usage of those systems. We have published two blog posts, one covering the p four chains vulnerabilities. You have the list of vulnerabilities there, SAP nodes, all the information, that I’ve been sharing with you is on the the blog post. Also, we released, last week the traditional patch analysis block. Right? There’s a block that is providing information about the patches that have been released by SAP on patch Tuesday. This blog post, authored by Thomas Bridge is very informative and containing all the information about the the different sub security notes, which are important, which you should be be addressing and and taking a look at. So I’m gonna briefly cover the support from the Onapsis platform perspective because, we continuously deliver content and protection to our customers through the technology of the Anapsis platform. In this case, let’s start with assess. This is the vulnerability management side of the house. Right? How do you know if there are vulnerabilities present on your system? Well, there are modules to identify these, nodes, these missing SAP security nodes or or these if those patches were, properly implemented or not. So module four five nine, if you run an assessment in the output of that module, you should be able to see these security notes. You have, on one hand, the CVE here, the security note related to that issue, and the the assessed finding, how you will see in OP as well. And, also, from an inventory perspective, if you wanna identify the SAP interbiportal systems to prioritize patching on those systems, module one zero one would be able if you run an assessment on your landscapes, it will tell you which ones are SAP enterprise portals as as a version as well. Visual here to see an example of one of those vulnerabilities and how you you get the description, the business impact, the technical solution, and all the information related to every each one of these vulnerabilities as with every other issue in OP. From a continuous monitoring perspective or threat detection, that would be our DEFEND module, we have a couple of points to cover. Before the patch Tuesday, we have been releasing since February zero day detection rules. So that means basically through your continuous monitoring capabilities, if there was active exploitation of those vulnerabilities, you will have been looking at that through the incident profile, OP chip, zero day exploit. So from February up until patch Tuesday, you have been covered from a different perspective. As of, patch Tuesday last week, those rules were compared into the standard exploitation rules and go through the standard detection mechanism of op sheet sock Java, because there is a patch available. Right? So there is basically a a substitute in our relay. It’s very important to keep your systems up to date because the automatic updates will give you all the content that we continuously ship. Even if there are changes to to this, if we see an exploit being published, if we see active exploitation, if we see new vulnerabilities or things like that that are related to, these p four chains and any other vulnerability affecting SAP applications, you will see those updates coming through automatic updates. So make sure you have data. Our recommendation is always automatic updates, but, if you have that disabled, you can do the manual update. Last but not least, the network detection rule pack. This is an add on that was released last year by Anapsis. So those customers that have the add on to defend have the IPS rules also to deploy in your IPS and and be able to block those if you want, depending on on your IPS deployment. Also, from a threat intelligence perspective, this is another capability that was released last year as well in the Anapsis platform. Is a capability that basically combines all of the output from the different modules on in OP into a unified or centralized pane of glass, showing what matters the most. In this case, we have an entry for b four chains that you will be able to see all the, individual vulnerabilities. You will be able to see, if there’s active exploitation of the system, if there’s information from DEFEND, information from ASSESS, from the the vulnerabilities that were patched or not, pointing to external sources, pointing to the blog post, pointing to any other information that is relevant. And this one as well will continuously be updated with new information as that information is evolving. I I already covered this, but I’m just stressing the fact that it’s very important to keep that update flow in OP so you get the latest and the greatest content that we, are shipping from the Anapsis Research Labs. Closing up, you have the links here to the two blog posts that I mentioned. One for the p four chains vulnerability and the other for the subnotes, the traditional, subnotes analysis blog post. So take a look at those. All the information that you need is in there, but we are happy to follow-up as needed on on any other additional information. So with that, I’m gonna pass it over to Cecile. I don’t know if we may have some questions. Perfect. Thank you very much, Stephanie, for those insights and let me check the Q and A box. Yes, I can see some coming in. The first one: Are these vulnerabilities being exploited in the wild yet? Okay, so to the moment we haven’t seen active exploitation to active exploits being executed on these vulnerabilities. It’s still, something that we’ll we’ll keep monitoring, and we’ll keep an eye because these are the type of vulnerabilities that get, get attention from from threat actors, and, it’s important to be, to act before threat actors do. So, for the moment, the answer is no, but we’ll we’ll keep monitoring. Okay. Thank you. Then the next one. You listed seven or so different vulnerabilities. Are all of them required for this remote access or is it just having one untouched creates the problem with this new vulnerability? Good. So yeah, I think I didn’t make it clear enough. It’s basically combining the portal vulnerabilities with any of the other ones would make this Internet exploitable. So it’s not that the attacker needs to combine all eight vulnerabilities. It’s the attacker through the portal vulnerability is able to exploit combining with that, exploit the the other p four vulnerabilities, any of them. Okay. And I would say we have time for one last question. To my knowledge, are other apps that use the P4 protocol. Is this something we should be concerned about? Are those at risk? Well, as I mentioned at the beginning, sorry, of the presentation, p four is a core protocol of SAP NetWear Java systems. So there are many, many p four services, and it’s extensively used by different products like Solman and BI and SAP enterprise products. So different p four services are gonna be deployed depending on the product that you have on top of the core NetWire Java. So to the moment, we know of these vulnerabilities, and these are the vulnerabilities that we need to patch. Right? So any other potential vulnerability or potential risk that, if if there’s another risk popping up, we will update, everyone, with the the right information and everything. But for the moment, these are the vulnerabilities. And and if there are other issues with other p four services, I’m sure SAP will release patches for for any other issues. So it’s important to focus today on those seven that we provided and keep on top of the P4 chains group of vulnerabilities. Perfect. Thank you. And that brings us to clients. For any other questions in the press, we will be reaching out to you individually to get those answers. And with that, thanks again Sophie and to everyone for joining this briefing. Have a good day. Thank you very much. Have a great day.