SAP Security Notes: May 2023 Patch Summary
In May 2023, SAP released critical security updates addressing vulnerabilities across several platforms, most notably SAP BusinessObjects (BOBJ) and the SAP 3D Visual Enterprise License Manager. These updates include patches for information disclosure, code injection, broken authentication, and session hijacking risks that require immediate attention from security administrators. Executive Summary The May 2023 SAP security […]
Is SAP ASE the Most Vulnerable Point in Your SAP Landscape?
SAP Adaptive Server Enterprise (ASE) is a widely-used relational database server for SAP solutions that requires specific security measures to prevent exploitation. While SAP HANA receives significant attention, ASE security is often overlooked, leaving it a vulnerable target for threat actors. Implementing automated vulnerability management, security patching, and real-time threat detection is essential for securing […]
SAP Security Notes: April 2023 Summary
In April 2023, SAP released several critical security notes addressing vulnerabilities in its software. Key patches included Note 3305369 for the SAP Diagnostics Agent, Note 3294595 for SAP NetWeaver AS ABAP, Note 3298961 for SAP BOBJ, and Note 3305907 for the BI Content Add-on for AS ABAP. The April 2023 SAP security update focused on […]
What’s New in the Cybersecurity Extension for SAP
The new release of the Cybersecurity Extension for SAP (CES) brings enhanced threat detection and configuration checks to SAP environments, including CVE/CVSS integration for security notes, directory traversal protection, and expanded Indicators of Compromise (IOC) patterns for Microsoft Server platforms, all designed to improve SAP security posture and compliance. Executive Summary The latest release of […]
SAP Security Notes: March 2023 Vulnerability Summary
What are the critical SAP security vulnerabilities addressed in March 2023? In March 2023, SAP released patches for several high-risk vulnerabilities, including a critical SQL injection in NetWeaver AS Java, authentication bypasses in the LockingService, and code execution risks in SAP BusinessObjects Business Intelligence (BOBJ). These updates are essential for maintaining system integrity and preventing […]
SAP Security Notes: Critical Vulnerabilities and Updates for February 2023
The February 2023 SAP Security Notes address critical vulnerabilities across NetWeaver Application Server Java, the SAP Host Agent, and SAP BusinessObjects. Key patches include fixes for JNDI interface exposure, privilege escalation via webservice requests, and unrestricted file upload vulnerabilities, alongside necessary corrections for side effects introduced by earlier security patches. Executive Summary The February 2023 […]
Analyzing Security Notes with SAP Maintenance Planner
SAP Maintenance Planner is a cloud-based solution that helps administrators identify, track, and manage SAP security notes and software updates. It simplifies landscape management by providing direct access to recommended notes—categorized by security, performance, and legal requirements—along with essential vulnerability data like CVE, CVSS, and vector information for each note. SAP Maintenance Planner serves as […]
SAP Security Notes: January 2023 Vulnerability Summary
The January 2023 SAP Security patch cycle addressed several critical and high-risk vulnerabilities, including a capture-replay issue in SAP NetWeaver AS ABAP and a broken authentication flaw in SAP NetWeaver AS Java. Organizations are advised to apply these security notes immediately to prevent unauthorized data access and potential service disruption. Executive Summary The January 2023 […]
How to Switch from SAP Code Vulnerability Analyzer to the Cybersecurity Extension for SAP, Part 9
The Cybersecurity Extension for SAP serves as a direct alternative to the SAP Code Vulnerability Analyzer (CVA) for managing SAP vulnerability assessments, threat detection, and custom code security. To transition, organizations must configure their SAP Solution Manager environment and establish a central check system using the ABAP Test Cockpit (ATC). Executive Summary The Cybersecurity Extension for SAP, […]
How to Switch from SAP Code Vulnerability Analyzer to the Cybersecurity Extension for SAP, Part 8
Switching from SAP Code Vulnerability Analyzer (CVA) to the Cybersecurity Extension for SAP requires a structured transition plan. Organizations must remove existing SAP CVA consoles, sensors, users, and addons from the landscape, then configure the Cybersecurity Extension as an addon within the SAP Solution Manager platform to maintain vulnerability management and threat detection. Executive Summary The transition […]