SAP Security Notes: August 2021 Summary
In August 2021, SAP released critical security updates addressing high-priority vulnerabilities across SAP NetWeaver, SAP S/4HANA, and SAP Business One. These patches resolve severe risks, including Server-Side Request Forgery (SSRF), SQL injection, and authentication bypasses, which could potentially lead to full system compromise if left unaddressed. What were the key SAP security updates in August […]
Securing the SYSTEM User in SAP HANA: Best Practices
The SYSTEM user is the most powerful database user in SAP HANA, possessing system-wide privileges to create users, modify system configurations, and manage databases. Because it is a well-known account with full administrative authority, it is a primary target for attackers. Securing this user is essential to preventing unauthorized system changes and data breaches. Why […]
SAP Security Notes: July 2021 Summary
In July 2021, SAP released critical security updates addressing vulnerabilities in SAP NetWeaver and the ABAP Platform. These patches resolve high-priority security risks, including broken authentication, missing authorization checks, and potential denial-of-service vectors, requiring immediate attention from security administrators to maintain system integrity. What were the key SAP security updates in July 2021? The July […]
SAP Security Notes: June 2021 Summary
In June 2021, SAP released critical security updates addressing vulnerabilities across SAP Commerce, SAP NetWeaver ABAP, and SAP NetWeaver AS Java. These patches resolve high-priority risks, including remote code execution, memory corruption, and unauthorized file system access, requiring immediate attention from security administrators. What is the critical remote code execution risk in SAP Commerce? Hot […]
Securing Software Supply Chains for SAP Landscapes
Software supply chain attacks are among the most sophisticated cyber threats, targeting information systems by compromising third-party software, builds, or trusted interfaces. By exploiting these dependencies, threat actors can introduce malicious backdoors into otherwise secure environments without detection. Why are software supply chain attacks a major risk for SAP? The catastrophic SolarWinds attack demonstrated how […]
Protecting SAP Systems from Ransomware Attacks: An Integrated Strategy
Ransomware attacks have surged by 300% over the past year, posing a critical threat to business infrastructure. While many organizations focus on hardening host operating systems, securing the underlying OS is insufficient for SAP environments. Attackers often exploit the trust relationships between SAP applications and the OS to execute privileged commands, bypass detection, and deploy […]
SAP Security Notes: May 2021 Summary
In May 2021, SAP released critical security patches addressing high-priority vulnerabilities across SAP NetWeaver AS ABAP, SAP Business One, and SAP Process Integration. These updates resolve significant risks including code injection, OS command injection, and information disclosure, requiring immediate action from security teams to prevent system compromise. What were the key SAP security updates in […]
Protecting SAP Systems from Ransomware Attacks
Recent high-profile incidents, such as the Colonial Pipeline attack, have highlighted the devastating impact of ransomware on critical infrastructure. With ransomware attacks increasing by 300% over the past year, organizations face significant operational risks: the average downtime from an attack is 21 days, while full recovery can take up to 287 days. Why host-level security […]
SAP Security Notes: April 2021 Summary
In April 2021, SAP released critical security updates addressing high-priority vulnerabilities across SAP Business Warehouse (BW), SAP Commerce, and SAP NetWeaver AS Java. These patches resolve severe risks, including remote code injection, privilege escalation, and information disclosure, requiring immediate attention from security administrators to maintain system integrity. What were the key SAP security updates in […]
Cybersecurity Extension for SAP Identifies Signatures of Active SAP Cyberattacks
Recent research confirms that attackers are actively targeting and weaponizing vulnerabilities in SAP applications. With some unprotected cloud installations being compromised in under three hours, and patches being weaponized in less than 72 hours, organizations must move beyond basic patching to implement active threat detection. The Reality of Active SAP Exploitation A joint report by […]