Security News

SAP Commerce Critical Security Bug Allows RCE
2021-02-10 21:32

SAP is warning of a critical vulnerability in its SAP Commerce platform for e-commerce businesses. Drools is an engine that makes up the rules engine for SAP Commerce.

Critical Vulnerability Patched in SAP Commerce Product
2021-02-10 14:18

SAP has released seven new security notes on February 2021 Security Patch Day, including a Hot News note that addresses a critical flaw in SAP Commerce. Tracked as CVE-2021-21477 and featuring a CVSS score of 9.9, the critical issue could be abused for remote code execution, SAP explains in its advisory.

Ivanti Velocity and Ivanti Speakeasy now optimized for SAP environments
2021-01-26 01:00

Ivanti Wavelink announced that Ivanti Velocity 2.1 and Ivanti Speakeasy 1.0 have achieved SAP certification as integrated with SAP S/4HANA and SAP NetWeaver. Adding SAP Extended Warehouse Management and the browser apps for the mobile internet transaction server component within SAP S/4HANA to its portfolio of supported solutions, Ivanti Wavelink brings a modern, mobile interface to SAP environments.

Beware! Fully-Functional Exploit Released Online for SAP Solution Manager Flaw
2021-01-23 19:35

Cybersecurity researchers have warned of a publicly available fully-functional exploit that could be used to target SAP enterprise software. The exploit leverages a vulnerability, tracked as CVE-2020-6207, that stems from a missing authentication check in SAP Solution Manager version 7.2.

SAP SolMan exploit released for max severity pre-auth flaw
2021-01-22 20:24

Fully-functional exploit code is now publicly available for a maximum severity pre-auth vulnerability impacting default configurations of an SAP Solution Manager component. SAP SolMan is an application lifecycle manager deployed in almost all SAP environments and designed to help unify the management of all SAP and non-SAP systems within a single interface.

Scanning Activity Detected After Release of Exploit for Critical SAP SolMan Flaw
2021-01-21 04:52

A Russian researcher has made public on GitHub a functional exploit targeting a critical vulnerability that SAP patched in its Solution Manager product in March 2020. Tracked as CVE-2020-6207 and featuring a CVSS score of 10, the security flaw is a missing authorization check in the EEM Manager component of SolMan, which could allow an unauthenticated, remote attacker to execute operating system commands on hosts, as the SMDAgent.

SAP appoints Julia White and Scott Russell to the Executive Board
2021-01-19 00:00

SAP announced that the Supervisory Board appointed Julia White and Scott Russell to the Executive Board. "We are very pleased to have both Julia and Scott join the Executive Board to help continue SAP's strategic direction," said Professor Hasso Plattner, chairman of the Supervisory Board of SAP SE. "We would also like to thank Adaire for her long-standing contribution to the company."

SAP Patches Serious Code Injection, DoS Vulnerabilities
2021-01-12 19:49

German software maker SAP has published 10 advisories to document flaws and fixes for a range of serious security vulnerabilities. Dealing with multiple vulnerabilities in SAP Business Warehouse, the most important of these issues carry a CVSS score of 9.9.

Virtustream Data Slicing and Masking Services for SAP: Automating and simplifying operations
2020-12-11 00:30

Virtustream announced Data Slicing and Masking Services for SAP, helping customers automate, copy and secure data in non-production environments. Virtustream's new Data Slicing and Masking Services for SAP solve these challenges through a full, end-to-end software implementation that delivers flexible data extraction, copy reduction, and masking and scrambling capabilities.

SAP Releases Four 'Hot News' Notes on December 2020 Patch Day
2020-12-09 13:51

SAP this week released eleven security notes as part of its December 2020 Security Patch Day, including four that were rated 'hot news. Featuring a CVSS score of 10, the most important of the notes addresses a missing authentication check vulnerability in SAP NetWeaver AS JAVA. Identified by security researchers at Onapsis, a firm that specializes in securing Oracle and SAP applications, the issue could allow an unauthenticated attacker to perform privileged actions over a TCP connection.