Layer Seven Security Blog

Stay up to date on the latest trends in SAP security, new threats and information on protecting your critical systems against an attack

SAP Zero Day Vulnerability CVE-2025-31324 / Security Note 3594142

Posted on
On April 22, ReliaQuest released details of a zero-day vulnerability that the company discovered during investigations into customer incidents involving the upload and execution of malicious files in SAP NetWeaver Java systems. According to the findings of the investigation, threat actors were able to take full control of the target systems by exploiting a vulnerability …
Read Article SAP Zero Day Vulnerability CVE-2025-31324 / Security Note 3594142

The 24-Month Rule for SAP Security Patching

Posted on
Regular patching is critical for protecting SAP software against security vulnerabilities. Security weaknesses are discovered by SAP through internal testing and testing performed by external researchers. The latter disclose vulnerabilities directly to the SAP Product Security Response Team and through the official SAP bug bounty program. Once a vulnerability is identified or reported, it is …
Read Article The 24-Month Rule for SAP Security Patching

SAP Security Notes, April 2025

Posted on
Hot news 3581961 patches a critical command injection vulnerability in SAP S/4HANA. Attackers can exploit a vulnerable remote-enabled function module using RFC to create a backdoor that bypasses authorization checks and provides full administrative access to the system. All releases of S/4HANA on-premise and private cloud are impacted. Corrections are included in the support package …
Read Article SAP Security Notes, April 2025

Proposed Changes to the Security Rule for HIPAA Compliance

Posted on
The Health Insurance Portability and Accountability Act (HIPAA) is a federal law in the United States that establishes minimum standards for securing Protected Health Information (PHI) including electronic PHI (ePHI). It applies to all organizations that store, process or transmit PHI for U.S citizens. PHI includes specific personal and health identifiers such as names, email …
Read Article Proposed Changes to the Security Rule for HIPAA Compliance

SAP Security Notes, March 2025

Posted on
Note 3563927 addresses a high-risk missing authorization check in SAP NetWeaver Application Server ABAP (AS ABAP) that could lead to an escalation of privileges. The correction included in the note restricts the ability to execute development functions using transaction SA38 from the ABAP Class Builder. SA38 enables program execution in AS ABAP. Authorization object S_PROGRAM …
Read Article SAP Security Notes, March 2025

Securing the SAP Cloud Connector

Posted on
The SAP Cloud Connector is an agent that links SAP BTP applications with on-premise SAP systems. As a reverse proxy, it enables internal systems to connect securely with BTP services without exposing the systems to direct external access. Permitted connections between BTP resources and backend systems can be maintained directly in the Cloud Connector rather …
Read Article Securing the SAP Cloud Connector

SAP Security Notes, February 2025

Posted on
Note 3417627 was updated in February to patch a high-risk cross-site scripting  vulnerability in the User Admin application of SAP NetWeaver AS Java. The vulnerability is to due to insufficient input validation and improper encoding. This allows an unauthenticated attacker to craft links containing malicious scripts. When a victim clicks on such a link, the …
Read Article SAP Security Notes, February 2025

SAP Security Notes, January 2025

Posted on
Hot news note 3537476 patches a critical vulnerability in SAP NetWeaver Application Server ABAP (AS ABAP) that enables attackers to exploit authentication weaknesses in the platform to compromise credentials in internal RFC communications and execute commands using the stolen credentials.  The vulnerability carries a CVSS base score of 9.9/10. The attack vectors to exploit the …
Read Article SAP Security Notes, January 2025

The Most Critical SAP Security Notes of 2024

Posted on
Security notes are released by SAP on the second Tuesday of every month to address vulnerabilities in SAP solutions. The vulnerabilities are discovered by external security researchers and reported as part of SAP’s disclosure program. They are also discovered directly by SAP through its’s ongoing research and testing. Security notes are scored by SAP using …
Read Article The Most Critical SAP Security Notes of 2024

SAP Security Notes, December 2024

Posted on
Hot news note 3536965 addresses multiple high risk vulnerabilities in Adobe Document Services (ADS) of SAP NetWeaver Application Server for JAVA (AS Java). This includes vulnerabilities for Server-Side Request Forgery (SSRF) and information disclosure. ADS should be updated to the recommended patch levels detailed in the note. There are no workarounds provided by SAP. Note …
Read Article SAP Security Notes, December 2024

Buyers Guide to SAP Enterprise Threat Detection

Posted on
SAP Enterprise Threat Detection (ETD) is the premier solution from SAP for identifying and responding to cyber attacks in SAP applications. ETD collects and analyzes log data from SAP systems and uses predefined patterns to detect Indicators of Compromise (IOCs) and trigger alerts for suspected security incidents. ETD includes graphical tools to support log analysis …
Read Article Buyers Guide to SAP Enterprise Threat Detection

SAP Security Notes, November 2024

Posted on
Note 3520281 patches a high priority Cross-Site Scripting (XSS) vulnerability in the SAP Web Dispatcher. The vulnerability can be exploited by attackers to execute arbitrary code and fully compromise Web Dispatcher installations. The vulnerability impacts users accessing the administration UI with a browser. The administration UI can be disabled as a workaround. This can be …
Read Article SAP Security Notes, November 2024

Cybersecurity Extension for SAP, Version 5.2: Support for SAP BTP, Critical Access and SOD for SAP ECC, and More

Posted on
The new release of the Cybersecurity Extension for SAP is scheduled for general availability in October and includes several important enhancements. Version 5.2 includes 40+ alerts for security related incidents in SAP BTP. This includes application changes, remote logins, role changes, role grants to users, and cloud transports. The alerts monitor events logged in the …
Read Article Cybersecurity Extension for SAP, Version 5.2: Support for SAP BTP, Critical Access and SOD for SAP ECC, and More

SAP Security Notes, October 2024

Posted on
Hot news note 3479478 was updated for a critical missing authentication check in SAP BusinessObjects (BOBJ) Business Intelligence Platform. The vulnerability can be exploited to compromise logon tickets used for Single Sign-On. The update provides a fix for BOBJ 4.2 SP009. The notes includes details of a workaround that will disable trusted authentication in the …
Read Article SAP Security Notes, October 2024

SAP Security Notes, September 2024

Posted on
Note 3459935 was updated in September with revised solution details to patch a high priority information disclosure vulnerability in SAP Commerce Cloud. Some OCC API endpoints in SAP Commerce Cloud allow Personally Identifiable Information (PII) data, such as passwords, to be included in the request URL as query or path parameters. The impacted endpoints are …
Read Article SAP Security Notes, September 2024

New Whitepaper: NIS2 Compliance for SAP Solutions

Posted on
The Network and Information Security (NIS2) Directive takes effect on October 17 and imposes significant requirements on organizations for cybersecurity and incident reporting. NIS2 mandates strict standards for cybersecurity and incident reporting for organizations that are based in the European Union or provide services within the EU. It is targeted at essential and important organizations …
Read Article New Whitepaper: NIS2 Compliance for SAP Solutions

SAP Security Notes, August 2024

Posted on
Hot news note 3477196 deals with a critical Server-Side Request Forgery (SSRF) vulnerability in applications built with SAP Build Apps. SAP Build Apps are vulnerable to CVE-2024-29415 due to the use of an older version of an Nodejs library included in software components for AppGyver. AppGyver is an open-source development platform used by SAP Build …
Read Article SAP Security Notes, August 2024

CrowdStrike Outage: Lessons Learned for SAP Solutions

Posted on
The fallout of the recent worldwide systems outage has far-reaching consequences for cybersecurity. The outage is estimated to impact 8.5 million devices powered by Microsoft Windows operating systems. The cause of the outage is a corrupted update for an agent used for the Falcon security platform from CrowdStrike. Falcon uses a cloud architecture with servers, …
Read Article CrowdStrike Outage: Lessons Learned for SAP Solutions

SAP Security Notes, July 2024

Posted on
Note 3483344 addresses a high-risk missing authentication check in SAP Product Design Cost Estimation (PDCE), included in the S4CORE component of SAP S/4HANA. The vulnerability can be exploited to escalate privileges and read sensitive information. The correction included in the note deactivates the affected functions to remove the vulnerability. There is no workaround provided by …
Read Article SAP Security Notes, July 2024

Cybersecurity Extension for SAP with SAP Focused Run

Posted on
SAP Focused Run (FRUN) is a Application Lifecycle Management (ALM) solution designed for real-time and high-volume system monitoring. It benefits from a more simplified and scalable architecture than other ALM platforms such as SAP Solution Manager (SolMan). Also, unlike SolMan, it runs exclusively with SAP HANA. System monitoring using FRUN is supported through the deployment …
Read Article Cybersecurity Extension for SAP with SAP Focused Run

SAP Security Notes, June 2024

Posted on
Note 3460407 patches a high priority denial of service vulnerability in the Meta Model Repository of SAP NetWeaver Application Server Java (AS Java). The vulnerability impacts version 7.50 of the software component MMR_SERVER. There are no workarounds available. Note 3457592 deals with reflected and stored cross-site scripting vulnerabilities SAP Financial Consolidation reported in CVE-2024-37177 and …
Read Article SAP Security Notes, June 2024