SAPwned: SAP AI vulnerabilities expose customers’ cloud environments and private AI artifacts
ID: b92b7a1d-4fc9-55b9-8be8-7950a929038a
STIX ID: report--b92b7a1d-4fc9-55b9-8be8-7950a929038a
Feed Name: Wiz Blog
Wiz Research performed tenant isolation testing on SAP AI Core and discovered a chain of vulnerabilities (including process-namespace sharing, misconfigured UIDs, exposed Istio tokens, leaked AWS credentials from Loki, unauthenticated EFS shares, and an exposed Helm/Tiller server) that enabled arbitrary code execution to escalate into cluster admin access, read/write access to internal registries and artifactory, and access to customer cloud credentials and AI artifacts; the findings were disclosed to SAP, patched, and no customer data compromise was reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
