Ghost in the Machine: Database Weaknesses Expose SAP Deployments Researchers announced last week glaring vulnerabilities in the way SAP interacts with the database layer that would allow remote attackers to own a company’s SAP systems — including controls that manage sensitive functions such as vendor and invoice creation simply by compromising the database that lies at the heart of an SAP deployment. Mariano Nunez Di Croce, a security researcher for Argentinean firm Onapsis, demonstrated attacks that showed how a malicious attacker can create a nearly undetectable ghost user account in SAP once he or she gains unauthorized access.






