Skip to content
Layer Seven Security Logo
  • Cybersecurity Extension for SAP
    • Product Information
    • Features
      • SAP RISE Security
      • S/4HANA Migration Security
      • Code Vulnerability Analysis for SAP
      • SIEM Integration for SAP
      • Access Risk Analysis for SAP
      • NIS2 Compliance for SAP
      • Virtual Patching for SAP
    • Buyers Guide
  • Services
    • SAP RISE Security Compliance
    • SAP Cybersecurity Assessment
    • SAP Penetration Testing
    • SAP Code Vulnerability Assessment
  • Success Stories
  • Resources
    • Case Studies
    • Whitepapers
    • News
    • Threat Reports & Advisories
  • Contact Us
Book a Demo
Book a Demo
Layer Seven Security Logo
Menu Icon

Layer Seven Security Blog

Stay up to date on the latest trends in SAP security, new threats and information on protecting your critical systems against an attack

EXECUTIVE SUMMARY

Leading the Conversation in SAP Cybersecurity

Our blog is the premier resource for CISOs and SAP security and Basis specialists seeking deep technical insights into the SAP threat landscape. Our research team provides expert analysis on emerging attack vectors targeting S/4HANA, SAP RISE, and SAP BTP, as well as practical guidance on meeting global compliance standards such as NIS2 and SOX. By translating complex vulnerability disclosures into actionable defense strategies, we empower the global SAP community to harden their mission-critical environments and implement proactive monitoring frameworks that bridge the gap between SAP teams and security operations.

Recent Articles & Threat Intel

Search

SAP Security Notes: August 2022 Summary

In August 2022, SAP released several critical security updates addressing vulnerabilities across SAP Knowledge Warehouse, SAP NetWeaver, and the SAP BusinessObjects (BOBJ) Business Intelligence Platform. These updates include critical patches for cross-site scripting (XSS) and various information disclosure vulnerabilities that could allow unauthorized access to sensitive system data. What were the key SAP security updates

Read Article

Securing Oracle Databases for SAP: Best Practices and Vulnerability Management

While many SAP customers are transitioning to S/4HANA, the majority still rely on conventional database platforms, with Oracle remaining one of the most common choices. Poorly configured Oracle databases can act as a major attack vector, allowing threat actors to bypass application-level security and compromise sensitive SAP data directly at the database layer. Why is

Read Article

SAP Security Notes: July 2022 Summary

In July 2022, SAP released several high-priority security notes addressing critical vulnerabilities in SAP Business One, SAP BusinessObjects (BOBJ), and SAP Landscape Management. These patches resolve significant risks, including information disclosure, code injection, and authentication bypasses that could lead to system compromise or denial of service. What were the primary security updates for SAP Business

Read Article

SAP Security Notes: June 2022 Summary

In June 2022, SAP released several critical security updates addressing vulnerabilities across SAProuter, SAP PowerDesigner Proxy, SAP Automotive Solutions, and SAP NetWeaver Application Server Java. These patches resolve high-priority risks, including remote command execution, privilege escalation, and unauthorized access to system services. What is the high-priority vulnerability in SAProuter? Note 3158375 addresses a critical vulnerability

Read Article

Reducing False Positives in SAP System Recommendations (SysRec)

SAP System Recommendations (SysRec) in Solution Manager is a vital tool for lifecycle management, yet analysis shows that approximately 30 percent of security notes reported are false positives. Because these irrelevant notes are often flagged due to system synchronization errors, organizations spend significant time manually filtering results, which delays critical security patching. What is the

Read Article

SAP Security Notes: May 2022 Summary

In May 2022, SAP released critical security updates addressing vulnerabilities across SAP NetWeaver, SAP BusinessObjects, SAP Business One Cloud, and Fiori UI components. These patches resolve significant risks, including remote code execution, information disclosure, and unauthorized access, requiring immediate attention from security administrators. What were the critical SAP security updates in May 2022? The May

Read Article

SAP Security Notes: April 2022 Summary

In April 2022, SAP released critical security updates addressing high-priority vulnerabilities, including the widespread Spring4Shell remote code execution flaw and serious code injection risks in SAP Manufacturing Integration and Intelligence (MII). These patches are essential for preventing unauthorized system access, privilege escalation, and service disruption. What is the impact of the Spring4Shell vulnerability on SAP?

Read Article

SAP Security Notes: March 2022 Summary

In March 2022, SAP released critical security updates addressing the high-profile ICMAD (Internet Communication Manager Advanced Desync) vulnerability, which posed a severe risk of remote system compromise. Additionally, SAP continued its efforts to mitigate the impact of the Log4Shell vulnerability by patching mobile components. What is the ICMAD vulnerability? The ICMAD (Internet Communication Manager Advanced

Read Article

SAP Security Notes: February 2022 Summary

In February 2022, SAP released several high-priority security updates, including new patches for the Log4Shell vulnerability and fixes for critical flaws in SAP Solution Manager and NetWeaver. These updates address risks ranging from remote code execution to SQL injection, necessitating prompt action from SAP security administrators. What were the key SAP security updates in February

Read Article

Protecting SAP Assets Against State-Sponsored Malware Threats

In response to heightened global cyber activity, the Cybersecurity and Infrastructure Security Agency (CISA) and the FBI have issued a joint statement urging organizations to strengthen their defensive posture. With the risk of destructive, state-sponsored malware spreading to business networks, organizations must prioritize the protection of mission-critical assets, particularly SAP environments, against advanced persistent threats. Why is

Read Article

Security Advisory: Critical SAP ICMAD Vulnerabilities (CVE-2022-22536)

International threat intelligence agencies, including CISA and CERT-EU, have issued urgent security advisories regarding the ICMAD (Internet Communication Manager Advanced Desync) vulnerabilities. These critical flaws affect the SAP Internet Communication Manager (ICM), a standard component of SAP NetWeaver and the SAP Web Dispatcher, and require immediate patching to prevent full system compromise. What is the

Read Article

SAP Security Notes: January 2022 Summary

In January 2022, SAP released multiple high-priority security updates, continuing the industry-wide response to the Log4Shell vulnerability and addressing significant security flaws in S/4HANA and NetWeaver Application Server ABAP. These patches are essential for mitigating risks related to remote code execution, malicious file uploads, and unauthorized system access. What were the key SAP security updates

Read Article
« Page1 … Page10 Page11 Page12 Page13 Page14 … Page27 »
Layer Seven Security Logo
  • Contact Us
  • Request a Demo
  • Our Company
  • Our Customers
  • Our Success Stories
  • Contact Us
  • Request a Demo
  • Our Company
  • Our Customers
  • Our Success Stories
  • Contact Us
  • Request a Demo
  • Our Company
  • Our Customers
  • Our Success Stories
  • Contact Us
  • Request a Demo
  • Our Company
  • Our Customers
  • Our Success Stories
Solutions
  • Cybersecurity Extension for SAP
  • Product Comparison
  • Cybersecurity Extension for SAP
  • Product Comparison
  • Cybersecurity Extension for SAP
  • Product Comparison
  • Cybersecurity Extension for SAP
  • Product Comparison
Services
  • SAP RISE Security Compliance
  • Cybersecurity Assessment
  • Code Vulnerability Assessments
  • Penetration Testing
  • SAP RISE Security Compliance
  • Cybersecurity Assessment
  • Code Vulnerability Assessments
  • Penetration Testing
  • SAP RISE Security Compliance
  • Cybersecurity Assessment
  • Code Vulnerability Assessments
  • Penetration Testing
  • SAP RISE Security Compliance
  • Cybersecurity Assessment
  • Code Vulnerability Assessments
  • Penetration Testing
Resources
  • Threat Reports & Advisories
  • Whitepapers
  • News
  • Threat Reports & Advisories
  • Whitepapers
  • News
  • Threat Reports & Advisories
  • Whitepapers
  • News
  • Threat Reports & Advisories
  • Whitepapers
  • News
Recent News

SAP Security Notes, September 2026

Managing Critical Access and Segregation of Duties Risks in SAP S/4HANA

SAP Security Notes, August 2026

SAP Security Notes, September 2026

Managing Critical Access and Segregation of Duties Risks in SAP S/4HANA

SAP Security Notes, August 2026

Browse Previous Content
Copyright © 2010-2026 Layer Seven Security Inc. All rights reserved.

Sitemap    Privacy Policy

The Gartner Peer Insights Logo is a trademark and service mark of Gartner, Inc., and/or its affiliates, and is used herein with permission. All rights reserved. Gartner Peer Insights reviews constitute the subjective opinions of individual end users based on their own experiences and do not represent the views of Gartner or its affiliates.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Layer Seven Security Logo
  • Cybersecurity Extension for SAP
    • Product Information
    • Features
      • SAP RISE Security
      • S/4HANA Migration Security
      • Code Vulnerability Analysis for SAP
      • SIEM Integration for SAP
      • Access Risk Analysis for SAP
      • NIS2 Compliance for SAP
      • Virtual Patching for SAP
    • Buyers Guide
  • Services
    • SAP RISE Security Compliance
    • SAP Cybersecurity Assessment
    • SAP Penetration Testing
    • SAP Code Vulnerability Assessment
  • Success Stories
  • Resources
    • Case Studies
    • Whitepapers
    • News
    • Threat Reports & Advisories
  • Contact Us