What’s New in the Cybersecurity Extension for SAP Version 2.0?

Version 2.0 of the Cybersecurity Extension for SAP is now available, introducing major enhancements to protect business-critical SAP solutions. Key updates include support for SAP NetWeaver AS Java, powerful anomaly detection capabilities, over 400 new threat detection patterns, and updated compliance checks for the latest SAP security benchmarks. Executive Summary Layer Seven Security’s release of the Cybersecurity […]

SAP Security Alert: Critical Patches for November 2025

SAP’s November 2025 security update includes critical patches for code execution, code injection, and insecure deserialization vulnerabilities. Key systems affected are SAP SQL Anywhere, SAP Solution Manager, and SAP NetWeaver AS Java. Administrators should prioritize the application of these patches to mitigate significant security risks. The November 2025 SAP Security Notes address several severe vulnerabilities […]

How to Conduct Penetration Testing for SAP RISE & Cloud ERP

Penetration testing for SAP RISE and Cloud ERP requires formal coordination with SAP Enterprise Cloud Services (ECS). Customers cannot test independently and must submit a formal request through the SAP support portal at least six weeks in advance, defining the scope, timeline, and testing provider. This process ensures testing adheres to SAP’s Rules of Engagement. […]

SAP Security Notes October 2025: Critical Vulnerabilities and Patches

SAP’s October 2025 security update addresses several critical and high-risk vulnerabilities, including two “Hot News” notes for insecure deserialization in SAP NetWeaver AS Java. These patches are crucial for preventing arbitrary OS command execution and protecting system integrity across multiple SAP products. This advisory summarizes the most significant patches released in October 2025. Key fixes […]

How to Find Workarounds for SAP Security Notes When Patching Isn’t an Option

When you can’t apply an official SAP patch for a vulnerability, workarounds are essential for mitigating risk. You can often identify these workarounds by analyzing the SAP Security Note itself. Details in the Symptom, Solution, and CVSS sections reveal clues, such as impacted objects to disable or access vectors to block through network filtering and […]

SAP Security Notes September 2025: Critical CVSS 10.0 Flaw in NetWeaver AS Java

SAP’s September 2025 security update includes the critical Hot News note 3634501, which addresses a CVSS 10/10 insecure deserialization vulnerability in SAP NetWeaver AS Java. This flaw could allow an attacker to execute arbitrary OS commands, leading to a full compromise of the affected Java systems. The SAP Security Notes for September 2025 are headlined […]

Layer Seven Security’s Cybersecurity Extension Named Top SAP Solution for 2025

Layer Seven Security’s Cybersecurity Extension for SAP has been named the Top SAP Cybersecurity Solution for 2025 by the Cybersecurity Review. The solution was selected for its superior integrated coverage, exceptional customer support, and competitive licensing costs, distinguishing it from competitors like Onapsis, Security Bridge, and Pathlock. The international publication, with nearly 300,000 subscribers, conducted a detailed analysis […]

SAP Security Notes August 2025: Critical Code Injection Flaws Patched

SAP’s August 2025 security update addresses multiple critical vulnerabilities, including two code injection flaws in SAP S/4HANA with CVSS scores of 9.9. These vulnerabilities, patched by notes 3581961 and 3627998, could allow attackers to install backdoors, bypassing all authorization checks and leading to full system compromise. The August 2025 SAP Patch Day delivered fixes for […]

Layer Seven Security’s Cybersecurity Extension Named Top SAP Solution for 2025

Layer Seven Security’s Cybersecurity Extension for SAP has been named the Top SAP Cybersecurity Solution for 2025 by the Cybersecurity Review. The solution was selected for its superior integrated coverage, exceptional customer support, and competitive licensing costs, distinguishing it from competitors like Onapsis, Security Bridge, and Pathlock. The international publication, with nearly 300,000 subscribers, conducted a detailed analysis […]

SAP Security Notes, July 2025: Critical Patches for Deserialization and Code Injection

The July 2025 SAP Security Notes feature several “hot news” patches for critical insecure deserialization vulnerabilities in SAP NetWeaver AS Java components. The most severe issue is a 10.0 CVSS score vulnerability in SAP SRM, alongside a critical code injection flaw in S/4HANA and SCM that could allow for a full system takeover. SAP’s July […]