SAP Security Notes February 2025: Key Vulnerabilities Explained

SAP’s February 2025 Security Patch Day addressed several high-priority vulnerabilities across its product portfolio. The updates include patches for a high-risk cross-site scripting (XSS) flaw in SAP NetWeaver AS Java, an information disclosure vulnerability in SAP BusinessObjects, a path traversal issue in SAP Supplier Relationship Management, and an open redirect vulnerability in SAP HANA. The […]

How Did a Ransomware Attack Lead Stoli Group USA to Bankruptcy?

The Stoli Group USA filed for Chapter 11 bankruptcy in November 2024 because a ransomware attack in August 2024 disabled its Enterprise Resource Planning (ERP) system. The resulting disruption forced the company to use manual bookkeeping, preventing it from meeting critical debt reporting requirements for its lenders. The Stoli Group USA, a major importer and […]

SAP Security Notes January 2025: Critical Vulnerabilities & Patches

SAP’s January 2025 security notes address several critical and high-risk vulnerabilities, most notably in SAP NetWeaver Application Server ABAP (AS ABAP). The release includes a critical 9.9 CVSS score patch for an authentication flaw that could allow credential theft and a separate high-risk patch for information disclosure due to a testing utility left in the […]

The Most Critical SAP Security Notes of 2024: A Complete Review

The most critical SAP security notes of 2024 addressed severe vulnerabilities, including two “hot news” notes with a 9.8 CVSS score. These critical patches fixed flaws like missing authentication in SAP BusinessObjects and code injection in SAP CX Commerce, which could lead to complete system compromise if left unpatched. In 2024, SAP released over 150 […]

SAP Security in Review: Analyzing the December 2024 Patch Notes

SAP’s December 2024 security notes address several high-risk vulnerabilities, including a Hot News note for Adobe Document Services (ADS) in AS Java. This critical patch tackles multiple flaws, such as Server-Side Request Forgery (SSRF) and information disclosure, for which SAP has provided no workarounds, urging immediate updates. This month’s security advisory outlines critical and high-risk […]

Buyer’s Guide: SAP Enterprise Threat Detection Drawbacks & Alternatives

While SAP Enterprise Threat Detection (ETD) is SAP’s primary solution for identifying cyber attacks in its applications, it has significant drawbacks regarding infrastructure, pattern coverage, and overall security scope. These limitations make addon-based, full-suite alternatives a more efficient and comprehensive choice for many organizations. SAP ETD is a powerful tool for detecting threats in real-time […]

SAP Security Notes November 2024: Critical Vulnerabilities and Patches

SAP’s November 2024 Security Notes address several high-priority vulnerabilities. The most critical is a Cross-Site Scripting (XSS) flaw in the SAP Web Dispatcher that allows for full compromise. Other key patches fix privilege escalation issues in SAP PDCE and SAP Host Agent, and authorization problems in NetWeaver AS Java. This advisory summarizes the key vulnerabilities […]

What’s New in Cybersecurity Extension for SAP, Version 5.2?

Version 5.2 of the Cybersecurity Extension for SAP introduces significant enhancements, including comprehensive support for SAP Business Technology Platform (BTP), critical access and Segregation of Duties (SoD) monitoring for SAP ECC, and new alerts for emerging threats. This release expands real-time threat detection and compliance monitoring across modern and legacy SAP environments. The latest update provides robust […]

SAP Security Notes October 2024: Analysis of Critical BOBJ and High-Risk Patches

The October 2024 SAP Security Notes feature a critical update for a missing authentication check in SAP BusinessObjects (BOBJ) that can compromise SSO tickets. Other high-risk notes address a file upload vulnerability in BOBJ, open-source library issues in SAP Enterprise Project Connection, and information disclosure in NetWeaver. SAP’s October 2024 security update is led by […]

How to Master Security Logging and Alerting for SAP BTP

Effective security for the SAP Business Technology Platform (BTP) requires robust logging and alerting. The primary methods involve using the central Audit Log, which can be integrated with external systems via the pull-based Audit Log Retrieval API, or using the push-based SAP Alert Notification Service for real-time event notifications. Both can be unified with SIEM […]