🧀 BigCheese.ai

Social

SAPwned: SAP AI vulnerabilities expose customers' cloud environments and privat

🧀

Wiz Research Team uncovered multiple vulnerabilities in SAP AI Core, potentially allowing attackers to compromise customer cloud environments and access sensitive AI artifacts. The vulnerabilities enabled unauthorized actions such as reading and modifying Docker images, gaining administrative Kubernetes cluster privileges, and obtaining cloud service credentials. All issues were responsibly disclosed and fixed by SAP before public disclosure.

  • AI infrastructure vulnerable to isolation issues.
  • SAP AI Core had multiple security flaws.
  • Sensitive customer AI data was at risk.
  • Attackers could modify AI artifacts.
  • All vulnerabilities are now patched.