logo

SAPwned: SAP AI vulnerabilities expose customers’ cloud environments and private AI artifacts

ID: b92b7a1d-4fc9-55b9-8be8-7950a929038a

STIX ID: report--b92b7a1d-4fc9-55b9-8be8-7950a929038a

Feed Name: Wiz Blog

Threat Score
80/100

Date Published: 2024-07-17

Date Updated: 2026-05-01

...
...

Wiz Research performed tenant isolation testing on SAP AI Core and discovered a chain of vulnerabilities (including process-namespace sharing, misconfigured UIDs, exposed Istio tokens, leaked AWS credentials from Loki, unauthenticated EFS shares, and an exposed Helm/Tiller server) that enabled arbitrary code execution to escalate into cluster admin access, read/write access to internal registries and artifactory, and access to customer cloud credentials and AI artifacts; the findings were disclosed to SAP, patched, and no customer data compromise was reported.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.