Security patches are released on the second Tuesday of each calendar month as part of SAP Security Patch Day. Security researchers and customers can report chess points to SAP as part of a “Responsible Disclosure” process. The resulting corrections are then presented to the SAP customer community on the following Patch Day. Customers can find the SAP Notes for the respective month on SAP Security Patch Day in Digital Asset Management.
Besides the PDF document, one can also select the security notes in the SAP Support Portal in the ONE Support Launchpad application “SAP Security Notes”.
Many leading software vendors follow a Patch Day ritual. Compared to a selective release, the bundled publication on a predictable date offers advantages for both customers and manufacturers. For example, customers don’t have to worry about missing an SAP Security Patch, while SAP can spend time between Security Patch Days identifying and fixing security vulnerabilities.
It is good practice for software vendors to give their customers and external security researchers the possibility to report potential vulnerabilities. These reports are received and processed as part of “Responsible Disclosure” based on the CERT policy for Coordinated Vulnerability Disclosure. It is common practice to name the researcher of vulnerability disclosure, and SAP does so with an SAP Security Patch Day.