SAP AI core flaw exposes sensitive customer data and keys

AI News


Security researchers have identified multiple vulnerabilities in SAP AI Core, a platform that allows users to develop, train, and run AI services.

These vulnerabilities, discovered by Wiz and described in an advisory published Wednesday, highlight significant risks associated with tenant isolation in AI infrastructure.

In particular, the SAP AI Core investigation revealed that an attacker could execute arbitrary code and access sensitive customer data and cloud credentials. This breach could allow malicious actors to manipulate internal artifacts and impact related services and other customer environments.

Wiz's findings showed that it was possible to read and modify Docker images on SAP's internal container registry and Google's Container Registry, obtain cluster admin privileges on SAP AI Core's Kubernetes cluster, and access customer cloud credentials and private AI artifacts.

Read more about AI in cybersecurity: OpenAI's ChatGPT violates GDPR, Noyb claims

The research began with a standard AI training procedure on SAP infrastructure that allowed arbitrary code execution. This capability allowed the team to circumvent network restrictions and exploit several configurations that the admission controller did not block.

These exploits allowed access to sensitive tokens and configurations, which led to further vulnerabilities, including unauthorized access to AWS secrets stored in Grafana Loki configurations and exposure of files on AWS Elastic File System instances.

Additionally, the team discovered an unauthenticated Helm server that provided access to highly privileged secrets in SAP's Docker registry and Artifactory servers. This access posed the risk of a supply chain attack where an attacker could contaminate images or builds. The most significant vulnerability they found was one that could allow an attacker to gain full cluster admin privileges on the Kubernetes cluster, giving them access to other customers' data and secrets.

All identified vulnerabilities were reported to SAP and subsequently fixed, and SAP confirmed that no customer data was compromised.

“This study highlights the unique challenges posed by the AI ​​research and development process,” Withe said. “Training AI, by definition, requires the execution of arbitrary code, so appropriate guardrails must be in place to ensure untrusted code is properly isolated from internal assets and other tenants.”

Image credit: Wirestock Creators / Shutterstock.com



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *