Skip to content
Layer Seven Security Logo
  • Cybersecurity Extension for SAP
    • Product Information
    • Features
      • SAP RISE Security
      • S/4HANA Migration Security
      • Code Vulnerability Analysis for SAP
      • SIEM Integration for SAP
      • Access Risk Analysis for SAP
      • NIS2 Compliance for SAP
      • Virtual Patching for SAP
    • Buyers Guide
  • Services
    • SAP RISE Security Compliance
    • SAP Cybersecurity Assessment
    • SAP Penetration Testing
    • SAP Code Vulnerability Assessment
  • Success Stories
  • Resources
    • Case Studies
    • Whitepapers
    • News
    • Threat Reports & Advisories
  • Contact Us
Book a Demo
Book a Demo
Layer Seven Security Logo
Menu Icon

Layer Seven Security Blog

Stay up to date on the latest trends in SAP security, new threats and information on protecting your critical systems against an attack

EXECUTIVE SUMMARY

Leading the Conversation in SAP Cybersecurity

Our blog is the premier resource for CISOs and SAP security and Basis specialists seeking deep technical insights into the SAP threat landscape. Our research team provides expert analysis on emerging attack vectors targeting S/4HANA, SAP RISE, and SAP BTP, as well as practical guidance on meeting global compliance standards such as NIS2 and SOX. By translating complex vulnerability disclosures into actionable defense strategies, we empower the global SAP community to harden their mission-critical environments and implement proactive monitoring frameworks that bridge the gap between SAP teams and security operations.

Recent Articles & Threat Intel

Search

How to switch from Onapsis to the Cybersecurity Extension for SAP, Part 5

The Cybersecurity Extension for SAP serves as a direct alternative to Onapsis for SAP vulnerability management, threat detection, and custom code security. This guide outlines the essential steps for configuring SAP Solution Manager to support your transition from Onapsis, ensuring your platform is ready to host the Cybersecurity Extension for SAP. Executive Summary Switching from Onapsis to

Read Article

How to switch from Onapsis to the Cybersecurity Extension for SAP, Part 4

Transitioning from Onapsis to the Cybersecurity Extension for SAP requires a strategic approach to SAP Solution Manager configuration. This guide outlines the infrastructure preparation steps necessary to ensure your platform is ready for the switch, allowing you to decommission Onapsis consoles, sensors, and addons securely. Why transition to the Cybersecurity Extension for SAP? The Cybersecurity Extension for SAP serves

Read Article

How to switch from Onapsis to the Cybersecurity Extension for SAP, Part 3

Switching from Onapsis to the Cybersecurity Extension for SAP involves removing legacy consoles and sensors while configuring the extension as an addon for SAP Solution Manager. The transition process requires verifying your Solution Manager environment, specifically completing the System Preparation steps within the Mandatory Configuration settings. The Cybersecurity Extension for SAP is an alternative for

Read Article

How to switch from Onapsis to the Cybersecurity Extension for SAP, Part 2

The Cybersecurity Extension for SAP is an SAP Solution Manager addon that serves as an alternative to Onapsis for SAP vulnerability management and threat detection. Transitioning requires verifying that your SAP Solution Manager environment is running version 7.2 with Support Pack 10 or higher to ensure compatibility and system support. Executive Summary Switching from Onapsis to the

Read Article

How to switch from Onapsis to the Cybersecurity Extension for SAP, Part 1

Transitioning from Onapsis to the Cybersecurity Extension for SAP allows organizations to manage SAP vulnerability management, threat detection, and custom code security directly within their existing SAP Solution Manager environment. This guide outlines the planning phase for migrating from Onapsis to Layer Seven Security’s integrated SAP solution. Why transition from Onapsis to the Cybersecurity Extension for SAP?

Read Article

SAP Security Notes, December 2022

In December 2022, SAP released critical security patches for vulnerabilities affecting SAP NetWeaver Application Server Java, SAP BusinessObjects, and SAP Commerce. These vulnerabilities include broken authentication, server-side request forgery, and remote code execution, requiring urgent implementation of security notes 3267780, 3273480, 3239475, and 3271523 to protect systems from exploitation. The December 2022 security updates addressed

Read Article

Securing the Journey to SAP S/4HANA: A Security Framework for S/4HANA Migrations

How can organizations secure their transition to SAP S/4HANA? Organizations must restructure access and technical controls to address significant differences between SAP ERP and S/4HANA. A comprehensive security framework, aligned with best practices, is essential to mitigate vulnerabilities during migration, especially when moving custom programs or transitioning to cloud-based S/4HANA installations. Executive Summary The transition

Read Article

SAP Security Notes, November 2022

The November 2022 SAP Security Notes address several critical and high-risk vulnerabilities, including a critical insecure deserialization flaw in the SAP BusinessObjects Business Intelligence Platform (BOBJ) and directory traversal issues in NetWeaver Application Server ABAP (AS ABAP). These updates are essential for maintaining the security of SAP environments. Executive Summary In November 2022, SAP released

Read Article

Securing Microsoft Platforms with the Cybersecurity Extension for SAP

The Cybersecurity Extension for SAP secures Microsoft platforms integrated with SAP by scanning for vulnerabilities across database and operating system layers. It detects over 300 security weaknesses in Microsoft SQL Server and Windows Server, while monitoring logs for indicators of compromise to prevent threat actors from bypassing application-level security. SAP systems are complex ecosystems where the application

Read Article

SAP Security Notes, October 2022

In October 2022, SAP released security patches addressing multiple critical vulnerabilities, including a URL redirection flaw in SAP Commerce Cloud (Note 3239152), a directory traversal vulnerability in SAP Manufacturing Execution (Note 3242933), an information disclosure risk in SAP BusinessObjects, and a denial-of-service vulnerability in SAP SQL Anywhere and SAP IQ. Executive Summary SAP’s October 2022

Read Article

SAP Security Notes, September 2022

The September 2022 SAP Security Patch Day addressed several high-priority vulnerabilities across the SAP ecosystem, including critical flaws in SAP GRC Access Control, BusinessObjects (BOBJ), SAP Business One, and SAP SuccessFactors. These patches resolve risks related to unauthorized access, privilege escalation, and information disclosure. Executive Summary The September 2022 security updates from SAP targeted critical

Read Article

How to Secure Custom SAPUI5 Applications Using the Cybersecurity Extension for SAP

Custom SAPUI5 applications are a core component of modern SAP environments, but they lack the native security patching provided by SAP, making them prime targets for attackers. To secure these applications, organizations must implement automated static source code scanning to identify and remediate vulnerabilities throughout the development lifecycle. Why is custom SAPUI5 application security critical?

Read Article
« Page1 … Page9 Page10 Page11 Page12 Page13 … Page27 »
Layer Seven Security Logo
  • Contact Us
  • Request a Demo
  • Our Company
  • Our Customers
  • Our Success Stories
  • Contact Us
  • Request a Demo
  • Our Company
  • Our Customers
  • Our Success Stories
  • Contact Us
  • Request a Demo
  • Our Company
  • Our Customers
  • Our Success Stories
  • Contact Us
  • Request a Demo
  • Our Company
  • Our Customers
  • Our Success Stories
Solutions
  • Cybersecurity Extension for SAP
  • Product Comparison
  • Cybersecurity Extension for SAP
  • Product Comparison
  • Cybersecurity Extension for SAP
  • Product Comparison
  • Cybersecurity Extension for SAP
  • Product Comparison
Services
  • SAP RISE Security Compliance
  • Cybersecurity Assessment
  • Code Vulnerability Assessments
  • Penetration Testing
  • SAP RISE Security Compliance
  • Cybersecurity Assessment
  • Code Vulnerability Assessments
  • Penetration Testing
  • SAP RISE Security Compliance
  • Cybersecurity Assessment
  • Code Vulnerability Assessments
  • Penetration Testing
  • SAP RISE Security Compliance
  • Cybersecurity Assessment
  • Code Vulnerability Assessments
  • Penetration Testing
Resources
  • Threat Reports & Advisories
  • Whitepapers
  • News
  • Threat Reports & Advisories
  • Whitepapers
  • News
  • Threat Reports & Advisories
  • Whitepapers
  • News
  • Threat Reports & Advisories
  • Whitepapers
  • News
Recent News

SAP Security Notes, September 2026

Managing Critical Access and Segregation of Duties Risks in SAP S/4HANA

SAP Security Notes, August 2026

SAP Security Notes, September 2026

Managing Critical Access and Segregation of Duties Risks in SAP S/4HANA

SAP Security Notes, August 2026

Browse Previous Content
Copyright © 2010-2026 Layer Seven Security Inc. All rights reserved.

Sitemap    Privacy Policy

The Gartner Peer Insights Logo is a trademark and service mark of Gartner, Inc., and/or its affiliates, and is used herein with permission. All rights reserved. Gartner Peer Insights reviews constitute the subjective opinions of individual end users based on their own experiences and do not represent the views of Gartner or its affiliates.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Layer Seven Security Logo
  • Cybersecurity Extension for SAP
    • Product Information
    • Features
      • SAP RISE Security
      • S/4HANA Migration Security
      • Code Vulnerability Analysis for SAP
      • SIEM Integration for SAP
      • Access Risk Analysis for SAP
      • NIS2 Compliance for SAP
      • Virtual Patching for SAP
    • Buyers Guide
  • Services
    • SAP RISE Security Compliance
    • SAP Cybersecurity Assessment
    • SAP Penetration Testing
    • SAP Code Vulnerability Assessment
  • Success Stories
  • Resources
    • Case Studies
    • Whitepapers
    • News
    • Threat Reports & Advisories
  • Contact Us