ANALYSIS OF SAP ERP SYSTEM VULNERABILITIES: INVESTIGATING THE RECON ISSUE AND ITS IMPACT ON INFORMATION SECURITY
I. Kh. Tashenov, Aigul Shaikhanova · Bulletin of Shakarim University Technical Sciences · 2024
Cyber threats are becoming increasingly sophisticated, posing a significant risk to enterprise resource planning (ERP) systems, such as SAP, which support the critical processes of large organizations. One of the most serious vulnerabilities in SAP is RECON (CVE-2020-6287), which received the maximum score of 10 on the CVSSv3 scale. Such a high rating indicates the critical danger of the vulnerability, allowing unauthorized attackers to gain administrative access to the systems. This can lead to data leaks, destabilization of business processes, and compromise of financial information.To address the RECON issue, the article examines three key tools. INSTANT RECON from Onapsis ensures rapid vulnerability detection, minimizing the time lag between discovery and remediation. Offline Security offers threat protection methods applied in isolated systems. SAP Enterprise Threat Detection (ETD) allows monitoring activity in real-time, preventing potential attacks. These tools play a crucial role in data protection and ensuring the stability of business processes. Their use helps enhance the resilience of ERP systems against internal and external threats, strengthening the overall information security of organizations.