Skip to content
Layer Seven Security Logo
  • Cybersecurity Extension for SAP
    • Product Information
    • Features
      • SAP RISE Security
      • S/4HANA Migration Security
      • Code Vulnerability Analysis for SAP
      • SIEM Integration for SAP
      • Access Risk Analysis for SAP
      • NIS2 Compliance for SAP
      • Virtual Patching for SAP
    • Buyers Guide
  • Services
    • SAP RISE Security Compliance
    • SAP Cybersecurity Assessment
    • SAP Penetration Testing
    • SAP Code Vulnerability Assessment
  • Success Stories
  • Resources
    • Case Studies
    • Whitepapers
    • News
    • Threat Reports & Advisories
  • Contact Us
Book a Demo
Book a Demo
Layer Seven Security Logo
Menu Icon

Layer Seven Security Blog

Stay up to date on the latest trends in SAP security, new threats and information on protecting your critical systems against an attack

EXECUTIVE SUMMARY

Leading the Conversation in SAP Cybersecurity

Our blog is the premier resource for CISOs and SAP security and Basis specialists seeking deep technical insights into the SAP threat landscape. Our research team provides expert analysis on emerging attack vectors targeting S/4HANA, SAP RISE, and SAP BTP, as well as practical guidance on meeting global compliance standards such as NIS2 and SOX. By translating complex vulnerability disclosures into actionable defense strategies, we empower the global SAP community to harden their mission-critical environments and implement proactive monitoring frameworks that bridge the gap between SAP teams and security operations.

Recent Articles & Threat Intel

Search

Securing SAP Solutions from Log4Shell: A Critical Guide

Log4Shell (CVE-2021-44228) is one of the most significant security vulnerabilities in decades. This zero-day remote code execution (RCE) flaw in the open-source Java logging utility, Log4j, allows unauthenticated attackers to remotely execute arbitrary code, potentially leading to a complete system compromise. Why is Log4Shell a major risk for SAP? Log4j is a widely used logging

Read Article

SAP Security Notes: December 2021 Summary

In December 2021, SAP released comprehensive security updates primarily focused on the critical Log4Shell (CVE-2021-44228) remote code execution vulnerability. This flaw, affecting the Apache Log4j 2 library, presented a severe risk to enterprise environments, requiring immediate patching and mitigation across multiple SAP solutions. Understanding the Log4Shell Vulnerability (CVE-2021-44228) Log4Shell is a critical vulnerability in the

Read Article

Securing SAP Systems from Log4J Exploits: A Critical Guide

The Log4Shell vulnerability (CVE-2021-44228) is one of the most serious security threats in recent decades. This remote code execution (RCE) flaw in the Apache Log4j logging framework allows unauthenticated attackers to remotely execute arbitrary code, potentially leading to the complete compromise of affected SAP applications and systems. What is the Log4J vulnerability? Log4j is an

Read Article

SAP Security Notes: November 2021 Summary

In November 2021, SAP released critical security updates addressing vulnerabilities across several key platforms, including SAP NetWeaver, SAP Solution Manager, and SAP Commerce. These patches resolve high-priority risks such as SQL injection, privilege escalation, and unauthorized access, requiring immediate attention from security administrators to maintain landscape integrity. What were the key SAP security updates in

Read Article

CISA Directive: Remediating Actively Exploited SAP Vulnerabilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive 22-01, mandating that government departments and agencies remediate specific vulnerabilities known to be actively exploited. This directive highlights six critical SAP vulnerabilities that pose significant risks to information systems, requiring remediation to ensure landscape security. What is the CISA Known Exploited Vulnerabilities (KEV)

Read Article

SAP Security Notes: October 2021 Summary

In October 2021, SAP released critical security updates addressing vulnerabilities across the NetWeaver, SAP Commerce, and Supply Chain Management platforms. These patches resolve high-priority security flaws, including broken authorization checks and XML External Entity (XXE) injection vulnerabilities, which could lead to unauthorized code execution or privilege escalation. What was the most critical update in October

Read Article

SAP Security Notes: September 2021 Summary

In September 2021, SAP released critical security updates addressing high-priority vulnerabilities across the NetWeaver, Knowledge Management, and Contact Center platforms. These patches resolve severe risks, including remote code execution, OS command injection, and improper input handling, requiring immediate attention from security administrators to protect SAP landscapes. What was the most critical update in September 2021?

Read Article

SAP Security Notes: August 2021 Summary

In August 2021, SAP released critical security updates addressing high-priority vulnerabilities across SAP NetWeaver, SAP S/4HANA, and SAP Business One. These patches resolve severe risks, including Server-Side Request Forgery (SSRF), SQL injection, and authentication bypasses, which could potentially lead to full system compromise if left unaddressed. What were the key SAP security updates in August

Read Article

Securing the SYSTEM User in SAP HANA: Best Practices

The SYSTEM user is the most powerful database user in SAP HANA, possessing system-wide privileges to create users, modify system configurations, and manage databases. Because it is a well-known account with full administrative authority, it is a primary target for attackers. Securing this user is essential to preventing unauthorized system changes and data breaches. Why

Read Article

SAP Security Notes: July 2021 Summary

In July 2021, SAP released critical security updates addressing vulnerabilities in SAP NetWeaver and the ABAP Platform. These patches resolve high-priority security risks, including broken authentication, missing authorization checks, and potential denial-of-service vectors, requiring immediate attention from security administrators to maintain system integrity. What were the key SAP security updates in July 2021? The July

Read Article

SAP Security Notes: June 2021 Summary

In June 2021, SAP released critical security updates addressing vulnerabilities across SAP Commerce, SAP NetWeaver ABAP, and SAP NetWeaver AS Java. These patches resolve high-priority risks, including remote code execution, memory corruption, and unauthorized file system access, requiring immediate attention from security administrators. What is the critical remote code execution risk in SAP Commerce? Hot

Read Article

Securing Software Supply Chains for SAP Landscapes

Software supply chain attacks are among the most sophisticated cyber threats, targeting information systems by compromising third-party software, builds, or trusted interfaces. By exploiting these dependencies, threat actors can introduce malicious backdoors into otherwise secure environments without detection. Why are software supply chain attacks a major risk for SAP? The catastrophic SolarWinds attack demonstrated how

Read Article
« Page1 … Page11 Page12 Page13 Page14 Page15 … Page27 »
Layer Seven Security Logo
  • Contact Us
  • Request a Demo
  • Our Company
  • Our Customers
  • Our Success Stories
  • Contact Us
  • Request a Demo
  • Our Company
  • Our Customers
  • Our Success Stories
  • Contact Us
  • Request a Demo
  • Our Company
  • Our Customers
  • Our Success Stories
  • Contact Us
  • Request a Demo
  • Our Company
  • Our Customers
  • Our Success Stories
Solutions
  • Cybersecurity Extension for SAP
  • Product Comparison
  • Cybersecurity Extension for SAP
  • Product Comparison
  • Cybersecurity Extension for SAP
  • Product Comparison
  • Cybersecurity Extension for SAP
  • Product Comparison
Services
  • SAP RISE Security Compliance
  • Cybersecurity Assessment
  • Code Vulnerability Assessments
  • Penetration Testing
  • SAP RISE Security Compliance
  • Cybersecurity Assessment
  • Code Vulnerability Assessments
  • Penetration Testing
  • SAP RISE Security Compliance
  • Cybersecurity Assessment
  • Code Vulnerability Assessments
  • Penetration Testing
  • SAP RISE Security Compliance
  • Cybersecurity Assessment
  • Code Vulnerability Assessments
  • Penetration Testing
Resources
  • Threat Reports & Advisories
  • Whitepapers
  • News
  • Threat Reports & Advisories
  • Whitepapers
  • News
  • Threat Reports & Advisories
  • Whitepapers
  • News
  • Threat Reports & Advisories
  • Whitepapers
  • News
Recent News

SAP Security Notes, September 2026

Managing Critical Access and Segregation of Duties Risks in SAP S/4HANA

SAP Security Notes, August 2026

SAP Security Notes, September 2026

Managing Critical Access and Segregation of Duties Risks in SAP S/4HANA

SAP Security Notes, August 2026

Browse Previous Content
Copyright © 2010-2026 Layer Seven Security Inc. All rights reserved.

Sitemap    Privacy Policy

The Gartner Peer Insights Logo is a trademark and service mark of Gartner, Inc., and/or its affiliates, and is used herein with permission. All rights reserved. Gartner Peer Insights reviews constitute the subjective opinions of individual end users based on their own experiences and do not represent the views of Gartner or its affiliates.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Layer Seven Security Logo
  • Cybersecurity Extension for SAP
    • Product Information
    • Features
      • SAP RISE Security
      • S/4HANA Migration Security
      • Code Vulnerability Analysis for SAP
      • SIEM Integration for SAP
      • Access Risk Analysis for SAP
      • NIS2 Compliance for SAP
      • Virtual Patching for SAP
    • Buyers Guide
  • Services
    • SAP RISE Security Compliance
    • SAP Cybersecurity Assessment
    • SAP Penetration Testing
    • SAP Code Vulnerability Assessment
  • Success Stories
  • Resources
    • Case Studies
    • Whitepapers
    • News
    • Threat Reports & Advisories
  • Contact Us