Responsible Disclosure: More Security for SAP Landscapes

20. July 2023

During SAP assessments, Nicolas Schickert, in charge of usd SAP-Pentests, discovered so-far unknown vulnerabilities in SAP products. These so-called zero-day vulnerabilities can have devastating effects. If these vulnerabilities were to become known, attackers could exploit them before the manufacturer can provide a suitable security patch. Our pentest professionals are aware of this responsibility and support manufacturers in developing timely solutions and closing critical security gaps. Therefore, the identified vulnerabilities were promptly reported to SAP within the "usd Responsible Disclosure" process and subsequently included in the "Acknowledgements to Researcher" document on the SAP website.

Nicolas Schickert emphasizes the importance of a specialized approach: "The discovery of these vulnerabilities in seemingly secure and standard-configured services highlights the importance of thoroughly examining such products not only through a security scan, but also through pentests. While a security scan can only identify known vulnerabilities, a pentest allows a deeper, individual and targeted search for vulnerabilities even beyond known gateways." 

Especially in highly complex SAP landscapes, in-depth expertise and detailed knowledge of the products are necessary to perform a comprehensive analysis of the current security standard. New security vulnerabilities often arise in this context due to configuration errors or individual circumstances. 

"Thanks to the open communication and efficient exchange between our colleagues and the development teams of SAP, the vulnerabilities could be fixed promptly. In this way, we were able to make an important contribution to the security of SAP products," Schickert adds. 

Detailed information about the advisories can be found here.

Also interesting:

Andrea Tubach is the new CEO of usd AG

Andrea Tubach is the new CEO of usd AG

Yesterday, at usd's Annual General Meeting and the subsequent meeting of the new Supervisory Board, long-prepared personnel changes were unanimously approved and then celebrated with an atmosphere of deep friendship: Andrea Tubach takes over as CEO. The founder and...

Security Advisories on Vtiger

Security Advisories on Vtiger

The pentest professionals at usd HeroLab examined Vtiger Open Source Edition 8.2.0 during the execution of their pentests. Our analysts discovered two vulnerabilities in the Vtiger software that allow low-privileged authorized users to upload files and execute...

NIS-2 Draft Bill under Examination: Everything You Need to Know

NIS-2 Draft Bill under Examination: Everything You Need to Know

A few days ago, the AG KRITIS published the latest draft bill on the NIS-2 Implementation Law (NIS2UmsuCG) on its website. Which requirements could become relevant for you if the law is passed in this version? Our experts have analyzed the draft for you and summarized...

Categories

Categories