SAP Security Notes September 2024: Key Vulnerabilities & Patches
SAP’s September 2024 security update addresses several key vulnerabilities, including a high-priority information disclosure flaw in SAP Commerce Cloud that could expose Personally Identifiable Information (PII). The patches also fix multiple Cross-Site Scripting (XSS) and authorization vulnerabilities across SAP NetWeaver, CRM, and Enterprise Portal, requiring immediate attention from administrators. This advisory summarizes the most significant […]
New Whitepaper: A Clear Path to NIS2 Compliance for SAP Solutions
A new whitepaper from Layer Seven Security provides a clear, actionable guide for achieving compliance with the EU’s NIS2 Directive for organizations running SAP. It details hardening standards, threat detection, and incident response mechanisms specifically for SAP environments, including guidance for SAP RISE, to meet the directive’s strict cybersecurity and reporting requirements. The European Union’s […]
SAP Security Notes August 2024: Critical Flaws in Build Apps and BOBJ
SAP’s August 2024 security advisories address several critical vulnerabilities, including a Server-Side Request Forgery (SSRF) in SAP Build Apps and a missing authentication check in SAP BusinessObjects Business Intelligence Platform (BOBJ). These high-priority patches require immediate attention to prevent potential system compromise and data leakage. The August 2024 SAP Patch Day released fixes for multiple […]
CrowdStrike Outage: Key Lessons for Securing SAP Solutions
The July 2024 worldwide systems outage, caused by a faulty update to CrowdStrike’s Falcon security platform, serves as a critical wake-up call for organizations running business-critical SAP solutions. The incident highlights the inherent risks of third-party security agents that operate at the kernel level, forcing a necessary re-evaluation of how to balance rapid threat response […]
SAP Security Notes July 2024: Key Vulnerabilities & Patches
SAP’s July 2024 security notes address several critical vulnerabilities, led by a high-risk missing authentication check in SAP S/4HANA. Also included are patches for a password misuse flaw in SAP Commerce, an information disclosure bug in SAP NetWeaver, and multiple cross-site scripting vulnerabilities. Executive Summary The July 2024 SAP Security Patch Day features several important […]
SAP Security Notes June 2024: High-Priority Fixes for AS Java and S/4HANA
SAP’s June 2024 Patch Day addresses several key vulnerabilities, including a high-priority denial of service issue in NetWeaver AS Java and privilege escalation flaws in S/4HANA and BW/4HANA. Organizations should prioritize applying these patches to mitigate risks of system downtime, data exposure, and unauthorized access. This summary covers the most significant security notes released on […]
What’s New in Cybersecurity Extension for SAP Version 5.1?
Version 5.1 of the Cybersecurity Extension for SAP introduces significant enhancements, including comprehensive access risk analysis for S/4HANA, compliance monitoring for SAP RISE, expanded threat detection patterns matching SAP ETD CE, and new dashboards for tracking actively and known exploited vulnerabilities based on the CISA KEV catalog. The latest release, version 5.1 of the Cybersecurity Extension for […]
SAP Security Notes May 2024: Analysis of Critical Patches
SAP’s May 2024 security update addresses several critical and high-risk vulnerabilities, led by a “Hot news” note for a file upload flaw in SAP NetWeaver. Other significant patches include fixes for remote code execution in SAP CX Commerce and multiple cross-site scripting (XSS) vulnerabilities in BusinessObjects and NetWeaver ABAP. The May 2024 SAP Security Notes […]
AI Agents Exploit 87% of Known Vulnerabilities: What This Means for SAP Security
A recent study from the University of Illinois has shown that AI agents, specifically using OpenAI’s GPT-4, can autonomously exploit security vulnerabilities with an 87% success rate when given access to CVE advisories. This groundbreaking research highlights the increasing risk of automated cyberattacks, significantly lowering the cost and complexity for threat actors. For organizations running […]
SAP Security Notes April 2024: Key Vulnerabilities and Patches
SAP’s April 2024 Security Patch Day addressed 10 new security notes, including three high-priority vulnerabilities. The most critical note, 3434839, tackles a security misconfiguration in SAP NetWeaver AS Java that could allow for weak passwords. Other significant patches address an information disclosure flaw in SAP BusinessObjects and a directory traversal vulnerability in SAP Asset Accounting. […]