Responsible Disclosure: More Security for SAP Landscapes

20. July 2023

During SAP assessments, Nicolas Schickert, in charge of usd SAP-Pentests, discovered so-far unknown vulnerabilities in SAP products. These so-called zero-day vulnerabilities can have devastating effects. If these vulnerabilities were to become known, attackers could exploit them before the manufacturer can provide a suitable security patch. Our pentest professionals are aware of this responsibility and support manufacturers in developing timely solutions and closing critical security gaps. Therefore, the identified vulnerabilities were promptly reported to SAP within the "usd Responsible Disclosure" process and subsequently included in the "Acknowledgements to Researcher" document on the SAP website.

Nicolas Schickert emphasizes the importance of a specialized approach: "The discovery of these vulnerabilities in seemingly secure and standard-configured services highlights the importance of thoroughly examining such products not only through a security scan, but also through pentests. While a security scan can only identify known vulnerabilities, a pentest allows a deeper, individual and targeted search for vulnerabilities even beyond known gateways." 

Especially in highly complex SAP landscapes, in-depth expertise and detailed knowledge of the products are necessary to perform a comprehensive analysis of the current security standard. New security vulnerabilities often arise in this context due to configuration errors or individual circumstances. 

"Thanks to the open communication and efficient exchange between our colleagues and the development teams of SAP, the vulnerabilities could be fixed promptly. In this way, we were able to make an important contribution to the security of SAP products," Schickert adds. 

Detailed information about the advisories can be found here.

Also interesting:

OWASP Top 10 2025 Released: Our Insights and Contribution

OWASP Top 10 2025 Released: Our Insights and Contribution

The OWASP Top 10 is considered the global standard for web application security. It highlights the main risks and indicates where companies should pay closer attention. The current Top 10 for 2025 was presented last week at OWASP Global AppSec USA 2025 and makes it...

EU AI Act: The 7 Most Important Questions

EU AI Act: The 7 Most Important Questions

The EU AI Act establishes the world's first comprehensive legal framework for artificial intelligence. What was previously considered a technological playground is now becoming a regulated responsibility. Artificial intelligence (AI) can no longer operate without...

Categories

Categories