How to Protect SAP Systems from SQL Injection Attacks Highlighted by FBI & CISA
The FBI and CISA have issued an urgent alert regarding the active exploitation of SQL injection vulnerabilities by cybercrime groups like CL0P (TA505). These attacks have resulted in significant ransomware extortion, underscoring the critical need for organizations to secure their software—especially custom applications running on platforms like SAP. This post breaks down the recent FBI […]
SAP Security Notes March 2024: AEO Optimized Summary
SAP’s March 2024 security updates addressed several critical and high-priority vulnerabilities requiring attention from administrators. The patches included two “Hot News” notes for code injection flaws in SAP Build Apps and SAP NetWeaver AS Java, alongside high-priority fixes for path traversal in BusinessObjects, Denial-of-Service in HANA XS, and an authentication flaw in SAP Commerce Cloud. […]
How to Ensure Security Compliance for SAP RISE Solutions
Securing SAP RISE solutions requires adhering to over 120 specific requirements across 12 security areas defined by SAP. Organizations can achieve this compliance by performing automated gap assessments using the Cybersecurity Extension for SAP (CES), which evaluates system settings against mandatory hardening standards to identify and remediate security vulnerabilities. SAP RISE customers, including those using […]
SAP Security Advisory: Summary of Critical Notes for February 2024
SAP’s February 2024 Security Patch Day addressed several critical and high-priority vulnerabilities across its product landscape, including a Hot News note for a code injection flaw. Key patches were released for SAP Application Basis (ABA), NetWeaver Application Server (AS) Java, SAP Cloud Connector, and SAP CRM. Administrators should prioritize the immediate application of these security […]
What is the SAP Cybersecurity Buyers Guide from SAPinsider?
The SAP Cybersecurity Buyers Guide from SAPinsider is an independent, expert-led assessment designed to help organizations evaluate technology vendors and consultants for SAP security. It provides critical insights into the capabilities required to protect mission-critical SAP environments against modern threats like ransomware, unauthorized access, and data breaches. Executive Summary As SAP landscapes evolve toward cloud-based […]
SAP Security Notes January 2024: Critical Vulnerabilities and Patches
The SAP Security Notes for January 2024 addressed several critical vulnerabilities, including two “Hot News” privilege escalation flaws in SAP Business Application Studio and Edge Integration Cell. A high-priority Denial of Service vulnerability in SAP NetWeaver’s ICM and a code injection flaw in the Application Interface Framework were also patched. This summary covers the key […]
SAP Security Advisory: Critical Patches for December 2023
SAP’s December 2023 security update includes critical patches for an OS command injection vulnerability in SAP S/4HANA and ECC, and high-risk vulnerabilities in the SAP Business Technology Platform (BTP). Organizations should prioritize the review and application of these notes to mitigate significant security risks. This advisory summarizes the key vulnerabilities and the required actions for […]
SAP Security Notes November 2023: Critical Business One Flaw and NetWeaver Patches
The SAP Security Notes for November 2023 featured a critical “Hot News” patch for a missing authentication vulnerability in SAP Business One, which registered a 9.6 CVSS score. Other key updates addressed a Cross-Site Request Forgery (CSRF) vulnerability in SAP Sybase and two separate information disclosure issues in SAP NetWeaver ABAP and Java servers. This […]
Security with SAP RISE: A Guide to the Shared Responsibility Model
In the SAP RISE model, security is a shared partnership. SAP manages the security of the underlying cloud infrastructure, including the hyperscaler environment, network, servers, and databases. The customer retains full responsibility for securing the application and data layers, which includes managing custom code, user access, and threat monitoring. While SAP provides a secure foundation, […]
SAP Security Notes: October 2023 Critical Updates
October 2023 SAP security updates addressed several critical and high-priority vulnerabilities, most notably a privilege escalation flaw in the SAP Common Cryptographic Library. Administrators are advised to update their systems, specifically applying Note 3340576, to secure impacted products including SAP NetWeaver, S/4HANA, and the SAP HANA Database. The October 2023 SAP security patch cycle targeted […]