How to switch from Onapsis to the Cybersecurity Extension for SAP, Part 4

Transitioning from Onapsis to the Cybersecurity Extension for SAP requires a strategic approach to SAP Solution Manager configuration. This guide outlines the infrastructure preparation steps necessary to ensure your platform is ready for the switch, allowing you to decommission Onapsis consoles, sensors, and addons securely. Why transition to the Cybersecurity Extension for SAP? The Cybersecurity Extension for SAP serves […]

How to switch from Onapsis to the Cybersecurity Extension for SAP, Part 3

Switching from Onapsis to the Cybersecurity Extension for SAP involves removing legacy consoles and sensors while configuring the extension as an addon for SAP Solution Manager. The transition process requires verifying your Solution Manager environment, specifically completing the System Preparation steps within the Mandatory Configuration settings. The Cybersecurity Extension for SAP is an alternative for […]

How to switch from Onapsis to the Cybersecurity Extension for SAP, Part 2

The Cybersecurity Extension for SAP is an SAP Solution Manager addon that serves as an alternative to Onapsis for SAP vulnerability management and threat detection. Transitioning requires verifying that your SAP Solution Manager environment is running version 7.2 with Support Pack 10 or higher to ensure compatibility and system support. Executive Summary Switching from Onapsis to the […]

How to switch from Onapsis to the Cybersecurity Extension for SAP, Part 1

Transitioning from Onapsis to the Cybersecurity Extension for SAP allows organizations to manage SAP vulnerability management, threat detection, and custom code security directly within their existing SAP Solution Manager environment. This guide outlines the planning phase for migrating from Onapsis to Layer Seven Security’s integrated SAP solution. Why transition from Onapsis to the Cybersecurity Extension for SAP? […]

SAP Security Notes, December 2022

In December 2022, SAP released critical security patches for vulnerabilities affecting SAP NetWeaver Application Server Java, SAP BusinessObjects, and SAP Commerce. These vulnerabilities include broken authentication, server-side request forgery, and remote code execution, requiring urgent implementation of security notes 3267780, 3273480, 3239475, and 3271523 to protect systems from exploitation. The December 2022 security updates addressed […]

Securing the Journey to SAP S/4HANA: A Security Framework for S/4HANA Migrations

How can organizations secure their transition to SAP S/4HANA? Organizations must restructure access and technical controls to address significant differences between SAP ERP and S/4HANA. A comprehensive security framework, aligned with best practices, is essential to mitigate vulnerabilities during migration, especially when moving custom programs or transitioning to cloud-based S/4HANA installations. Executive Summary The transition […]

SAP Security Notes, November 2022

The November 2022 SAP Security Notes address several critical and high-risk vulnerabilities, including a critical insecure deserialization flaw in the SAP BusinessObjects Business Intelligence Platform (BOBJ) and directory traversal issues in NetWeaver Application Server ABAP (AS ABAP). These updates are essential for maintaining the security of SAP environments. Executive Summary In November 2022, SAP released […]

Securing Microsoft Platforms with the Cybersecurity Extension for SAP

The Cybersecurity Extension for SAP secures Microsoft platforms integrated with SAP by scanning for vulnerabilities across database and operating system layers. It detects over 300 security weaknesses in Microsoft SQL Server and Windows Server, while monitoring logs for indicators of compromise to prevent threat actors from bypassing application-level security. SAP systems are complex ecosystems where the application […]

SAP Security Notes, October 2022

In October 2022, SAP released security patches addressing multiple critical vulnerabilities, including a URL redirection flaw in SAP Commerce Cloud (Note 3239152), a directory traversal vulnerability in SAP Manufacturing Execution (Note 3242933), an information disclosure risk in SAP BusinessObjects, and a denial-of-service vulnerability in SAP SQL Anywhere and SAP IQ. Executive Summary SAP’s October 2022 […]

SAP Security Notes, September 2022

The September 2022 SAP Security Patch Day addressed several high-priority vulnerabilities across the SAP ecosystem, including critical flaws in SAP GRC Access Control, BusinessObjects (BOBJ), SAP Business One, and SAP SuccessFactors. These patches resolve risks related to unauthorized access, privilege escalation, and information disclosure. Executive Summary The September 2022 security updates from SAP targeted critical […]