
Senior SAP Developer (ABAP/4 and SAPUI5 Fiori) – Singapore
As a Senior SAP Developer, you will be responsible for designing, developing, and maintaining SAP solutions while leading and guiding a team of developers. You
On February 2022, the US Cybersecurity and Infrastructure Security Agency (CISA) warned administrators about a series of critical security vulnerabilities known as ICMAD (Internet Communication Manager Advanced Desync). These vulnerabilities specifically affect SAP business applications that utilize Internet Communication Manager (ICM). As a leading cybersecurity platform for SAP systems, we took a closer look at what ICMAD is, what vulnerabilities are part of it, and how you can protect your systems. Read on to learn all about it.
The SAP ICM, which stands for Internet Communication Manager, is a component of the SAP NetWeaver Application Server for ABAP (an SAP system). It operates as an independent process initiated and managed by the ABAP dispatcher. The primary function of the ICM is to facilitate communication between the SAP System and external entities. When operating in the server role, it handles incoming requests from the internet, and based on the URL received, it triggers the appropriate local handler for further processing.
The ICM has many security-relevant configurations for SSL encryption, cookie handling, authentication requests (HTTP) and even provides a dedicated security log. Tools like SecurityBridge Security & Compliance Management assess the secure setup of the ICM in SAP NetWeaver and offer guidance to customers on strengthening the security of their webserver.
SAP ICMAD Vulnerabilities are those vulnerabilities that are present in the ICM component of SAP, including SAP NetWeaver, S/4HANA, and SAP Web Dispatcher. There are three ICMAD vulnerabilities:
These vulnerabilities can significantly impact businesses and are especially critical due to the following factors:
Now that you know what ICMAD is and which vulnerabilities are part of it, you’re probably wondering how to protect your systems. These vulnerabilities highlight the critical need for organizations to prioritize vulnerability management and adopt robust security measures. Mitigating these vulnerabilities requires a comprehensive approach that includes patching, configuration hardening, and constant monitoring of the SAP landscape. Implementing a solution like SecurityBridge Vulnerability Management can help your organization effectively address ICMAD vulnerabilities, and with our SecurityBridge Patch Management solution, you can easily reduce the risk of exploitation. Additionally, this allows SAP security teams to efficiently safeguard their critical systems and data assets from potential threats.
Did we help you figure out what ICMAD is? Did we catch your eye, and do you want to learn how we can help protect your SAP systems? Don’t be shy. Reach out to us to book a free demo, and we will help you take your SAP security to the next level.
Posted by
Find recent Security Advisories for SAP©
Looking into securing your SAP landscape? This white-paper tells you the “Top Mistakes to Avoid in SAP Security“. Download it now.
As a Senior SAP Developer, you will be responsible for designing, developing, and maintaining SAP solutions while leading and guiding a team of developers. You
Earlier this year, IBM presented its 18th edition of ‘The Cost of a Data Breach Report’ (you can find it here). This publication provides detailed
This blog explores AI’s role in SAP Security, security platform challenges and the need for system hardening.