logo

SAP AI Core Vulnerabilities Expose Customer Data to Cyber Attacks

ID: 6b135e6c-751f-5bfd-91da-68f65c49821c

STIX ID: report--6b135e6c-751f-5bfd-91da-68f65c49821c

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-07-18

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed five vulnerabilities in SAP AI Core ("SAPwned") that could let attackers access customer data and cloud credentials (AWS, Azure, SAP HANA), modify Docker/container artifacts, and escalate to Kubernetes cluster admin — creating a realistic supply-chain and cross-tenant compromise risk; the issues were responsibly disclosed on 2024-01-25 and patched by SAP on 2024-05-15. The report additionally highlights the broader ecosystem risk from criminal groups like NullBulge that target AI and gaming services using info-stealers, RATs, and ransomware payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.