How to Secure Custom SAPUI5 Applications Using the Cybersecurity Extension for SAP

Custom SAPUI5 applications are a core component of modern SAP environments, but they lack the native security patching provided by SAP, making them prime targets for attackers. To secure these applications, organizations must implement automated static source code scanning to identify and remediate vulnerabilities throughout the development lifecycle. Why is custom SAPUI5 application security critical? […]

SAP Security Notes: August 2022 Summary

In August 2022, SAP released several critical security updates addressing vulnerabilities across SAP Knowledge Warehouse, SAP NetWeaver, and the SAP BusinessObjects (BOBJ) Business Intelligence Platform. These updates include critical patches for cross-site scripting (XSS) and various information disclosure vulnerabilities that could allow unauthorized access to sensitive system data. What were the key SAP security updates […]

Securing Oracle Databases for SAP: Best Practices and Vulnerability Management

While many SAP customers are transitioning to S/4HANA, the majority still rely on conventional database platforms, with Oracle remaining one of the most common choices. Poorly configured Oracle databases can act as a major attack vector, allowing threat actors to bypass application-level security and compromise sensitive SAP data directly at the database layer. Why is […]

SAP Security Notes: July 2022 Summary

In July 2022, SAP released several high-priority security notes addressing critical vulnerabilities in SAP Business One, SAP BusinessObjects (BOBJ), and SAP Landscape Management. These patches resolve significant risks, including information disclosure, code injection, and authentication bypasses that could lead to system compromise or denial of service. What were the primary security updates for SAP Business […]

SAP Security Notes: June 2022 Summary

In June 2022, SAP released several critical security updates addressing vulnerabilities across SAProuter, SAP PowerDesigner Proxy, SAP Automotive Solutions, and SAP NetWeaver Application Server Java. These patches resolve high-priority risks, including remote command execution, privilege escalation, and unauthorized access to system services. What is the high-priority vulnerability in SAProuter? Note 3158375 addresses a critical vulnerability […]

Reducing False Positives in SAP System Recommendations (SysRec)

SAP System Recommendations (SysRec) in Solution Manager is a vital tool for lifecycle management, yet analysis shows that approximately 30 percent of security notes reported are false positives. Because these irrelevant notes are often flagged due to system synchronization errors, organizations spend significant time manually filtering results, which delays critical security patching. What is the […]

SAP Security Notes: May 2022 Summary

In May 2022, SAP released critical security updates addressing vulnerabilities across SAP NetWeaver, SAP BusinessObjects, SAP Business One Cloud, and Fiori UI components. These patches resolve significant risks, including remote code execution, information disclosure, and unauthorized access, requiring immediate attention from security administrators. What were the critical SAP security updates in May 2022? The May […]

SAP Security Notes: April 2022 Summary

In April 2022, SAP released critical security updates addressing high-priority vulnerabilities, including the widespread Spring4Shell remote code execution flaw and serious code injection risks in SAP Manufacturing Integration and Intelligence (MII). These patches are essential for preventing unauthorized system access, privilege escalation, and service disruption. What is the impact of the Spring4Shell vulnerability on SAP? […]

SAP Security Notes: March 2022 Summary

In March 2022, SAP released critical security updates addressing the high-profile ICMAD (Internet Communication Manager Advanced Desync) vulnerability, which posed a severe risk of remote system compromise. Additionally, SAP continued its efforts to mitigate the impact of the Log4Shell vulnerability by patching mobile components. What is the ICMAD vulnerability? The ICMAD (Internet Communication Manager Advanced […]

SAP Security Notes: February 2022 Summary

In February 2022, SAP released several high-priority security updates, including new patches for the Log4Shell vulnerability and fixes for critical flaws in SAP Solution Manager and NetWeaver. These updates address risks ranging from remote code execution to SQL injection, necessitating prompt action from SAP security administrators. What were the key SAP security updates in February […]