Ignacio Favro is a Senior Security Researcher at Onapsis, where he specializes in identifying and mitigating vulnerabilities in business-critical applications. With a background in computer science and extensive experience in cybersecurity, Ignacio plays a pivotal role in advancing the security research efforts of Onapsis. His contributions focus on safeguarding enterprise systems, including SAP, by uncovering risks and developing strategies to enhance cyber resilience.
In Episode 1 of our new docuseries, Hacking & Defending SAP Applications Live, Onapsis researchers Ignacio Favro and Fabian Hagg analyzed the first mass-exploited SAP zero-day (CVE-2025-31324 and CVE-2025-42999). Sophisticated threat actors leveraged this previously unknown flaw to compromise hundreds of SAP customers. This article serves as a practitioner’s recap of that session, breaking down…
Last Updated: 12/19/2025 Introduction to Hash Cracking The Bottom Line: SAP systems frequently prioritize backward compatibility, leading to the storage of weak, easily crackable password hashes (such as MD5-based CODVN B) alongside stronger modern standards. Attackers exploit this by extracting these legacy hashes from database tables like USR02 and USH02 to compromise user credentials—even if…
Discover your SAP security maturity with our new interactive self-assessment. Get personalized recommendations.
Start Now
Learn how to build cyber resilience during your SAP cloud migration journey.
Watch Now
Executive overview of a reported SAP cyber attack that severely impacted business operations.
Read Now
We are bridging the gap between theoretical risk and practical defense, directly sourced from our experience on the SAP cybersecurity front lines.
Watch Now
Discover why leading enterprises tryst Onapsis to secure their most critical business applications
Read More