cancel
Showing results for 
Search instead for 
Did you mean: 

New vulnerabilities in BusinessObjects and HANA uncovered

Former Member
0 Kudos

Hi,

Today InsideSAP.com.au has release an article about: "New vulnerabilities in BusinessObjects and HANA uncovered". You can read the article using this link: New vulnerabilities in BusinessObjects and HANA uncovered

I have to say that I am very disappointed to hear that from the media and not from SAP. I have raised a ticket for this as an incident and I would like to let everyone know about this.

Regards,

Garyl

Accepted Solutions (0)

Answers (5)

Answers (5)

Former Member
0 Kudos

Thanks for the Info guys. I now understand how this was handled. The article did not mention any of that.

denis_konovalov
Active Contributor
0 Kudos

That is why you do not trust any articles on the internet that do not have a full picture, always check at the source !

former_member184468
Active Participant
0 Kudos

SAP regularly releases SAP security notes.  SAP's "patch Tuesday" happens on the same day as Microsoft actually for anyone who is familiar with the security patch strategy there.   SAP security notes is how SAP communicates its security fixes, for all its products. 

denis_konovalov
Active Contributor
0 Kudos

This inside.sap.au has done a very bad job on reporting this issue.
All vulnerabilities discovered by Onapsis are documented in SAP Notes and are fixed in corresponding patches or SP's.
This is described in Onapsis advisories themselves on the Onapsis web site.

SAP is constantly on the lookout for any possible security vulnerabilities and if they are discovered in-house or outside - there are fixed as soon as possible.

denis_konovalov
Active Contributor
0 Kudos

got info that this was reported to SAP and was already patched.

denis_konovalov
Active Contributor
0 Kudos

I hope company that found those "potential" vulnerabilities has contacted SAP and provided details, so it can be reviewed and addressed if needed.