Recent Updates – February 2022

SAP stability and new features

In Version 6.04 of the SecurityBridge Platform we introduced new capabilities and general product improvements for SAP Security, often originating from customer feedback and industry requirements.

The highlights below are just a sample of the innovations introduced with the latest release of the SecurityBridge Platform. Customers can find a complete overview in the Release Notes.

Log4j Vulnerability Scanning

Immediately after the Log4j became public SecurityBridge delivered new signatures for two existing Threat Detection Sensors (1082 and 1086) contained in the SecurityBridge Platform.

With these SecurityBridge SAP customers are secured by default against the Log4j vulnerability.

New SAP Security Baseline

The Security & Compliance Management was updated with a new security baseline that checks the requirements provided by the German SAP user group (DSAG) who provided a distinct SAP Security Recommendation Guideline.

So, this new baseline now makes the best practices and recommendations available for all SecurityBridge customers.

Action rule configuration via Settings App

The very powerful Action & Filters feature received not enough attention yet as it was only available via SAP Gui transactions. That’s why we have now brought it to the Fiori frontend.

With Action & Filters SecurityBridge users can automate actions for detected security findings. E.g. the moment a system will be opened for change, an email is sent immediately (and automatically) to the system owner.

Relevant settings are now easily accessible via the web-based editor.

Code Vulnerability Analyzer updated

We added KPI metrics to the dashboard of this Code Vulnerability Analyser app. These KPIs increase transparency and make it easier to rate the security posture of an SAP system.

... stay tuned

Our new module Violation Management is coming soon.

Posted by

Till Pleyer
Find recent Security Advisories for SAP©

DSAG-Jahreskongress 2023

Alles verändert sich, nichts bleibt wie es ist, die heutige Zeit setzt Flexibilität voraus. Entsprechend wandelbar präsentieren sich DSAG, SAP und das gesamte Ökosystem. Diese Wandlungsfähigkeit steht auch im Fokus des DSAG-Jahreskongress 2023 vom 19.-21. September 2023 in Bremen. Unter dem Motto „Wunderbar wandelbar – Gemeinsam neue Perspektiven schaffen“ freut sich die DSAG wieder darauf, mehr als 5.000 Teilnehmende zu begrüßen. Wagen Sie gemeinsam mit der Interessenvertretung den Blick durch das Kaleidoskop und finden Sie den richtigen Dreh, um zu neuen Blickwinkeln zu gelangen und Veränderungen zu gestalten.
Download the White Paper “Bridging the Gap – How SecurityBridge Supports NIST CSF in SAP Environments”. Learn how choosing the right tool can significantly shorten the journey of NIST CSF adoption and improve the security posture of SAP environments.
DSAG Jahreskongress 2023
Alles verändert sich, nichts bleibt wie es ist, die heutige Zeit setzt Flexibilität voraus. Entsprechend wandelbar präsentieren sich DSAG, SAP und das gesamte Ökosystem. Diese Wandlungsfähigkeit steht auch im Fokus des DSAG-Jahreskongress 2023 vom 19.-21. September 2023 in Bremen. Unter dem Motto „Wunderbar wandelbar – Gemeinsam neue Perspektiven schaffen“ freut sich die DSAG wieder darauf, mehr als 5.000 Teilnehmende zu begrüßen. Wagen Sie gemeinsam mit der Interessenvertretung den Blick durch das Kaleidoskop und finden Sie den richtigen Dreh, um zu neuen Blickwinkeln zu gelangen und Veränderungen zu gestalten.
SAP security Patch day
SAP Security Patch Day
Today is another SAP Security Patch Day. In May 2023, the SAP Response Team released 20 SAP Security Notes, including Evergreen 2622660 Security updates for the browser control Google Chromium delivered with SAP Business Client with HotNews priority. Besides two updated Notes, SAP Security Patch Day May 2023, contains 18 new security updates for the vast SAP Product portfolio while the majority relates to SAP Business Objects.
SAP ABAP Directory Traversal Vulnerability
SAP developers know that ABAP/4 (Advanced Business Application Programming) is not immune to security vulnerabilities like any other programming language. One significant security risk associated with SAP ABAP is directory traversal vulnerability. In this blog post, we will discuss what a directory traversal vulnerability is, why it is a problem for SAP customers, how it can be exploited, and what measures to take to prevent it.