All vulnerabilities
CRITICALAI/LLMexploited in the wild

AI-SAPWNED-2024

SAP AI Core · SAP AI Core

Summary

Wiz Research chained five weaknesses to break tenant isolation on SAP AI Core in research dubbed SAPwned. By submitting a legitimate-looking training job, they configured pods to steal Istio sidecar tokens and bypass network segmentation, then reached unauthenticated internal services including a Grafana Loki instance leaking AWS credentials, an unauthenticated EFS share and an exposed Helm Tiller server. Using Helm's write access they deployed a malicious package granting cluster-admin, gaining cross-tenant access to other customers' pods, secrets, cloud credentials and private AI artifacts. SAP fixed all issues by May 2024 and stated no customer data was compromised.

How to avoid it in your code

  • Apply SAP's fixes (patched by May 2024) and keep AI Core platform components updated.
  • Enforce strong tenant isolation and network segmentation; block pods from reaching internal services.
  • Lock down service tokens, internal logging, shares and Helm with auth and least privilege.
  • Treat training-job inputs as untrusted; sandbox workloads and restrict cluster RBAC.
  • Rotate exposed cloud credentials and audit cross-tenant access paths.

References

Related vulnerabilities

All AI/LLM →