Founded in 1972, SAP is a leading provider of business software solutions and applications. According to total market capitalization, SAP is the third largest software manufacturer in the world with over 230,000 customers in more than 180 countries.
But here comes the bad news.
A staggering 95% of SAP 's enterprise software applications contain high-severity vulnerabilities that could allow compromise, researchers report.
Researchers from security firm Onapsis report that attackers can target all SAP installs, execute commands with admin privileges, and create J2EE backdoors.
Onapsis CEO Mariano Nunez says that SAP's 250,000 customers are exposed on average 18 months from the moment the vulnerabilities are discovered, since SAP needs about 12 months to develop a patch that "fixes" them.
“The truth is that most patches that are applied are irrelevant to security, come late, or introduce code that guarantees further risks.”
The Boston firm discovered that SAP had released 391 patches in recent years, half of which were marked as high priority.
Nunez partly blames the SAP HANA feature for this whole situation, which he says is responsible for a 450% increase in the number of security patches.
“This trend not only does not continue, but is exacerbated with SAP HANA … which is positioned at the center of the SAP ecosystem where data from SAP platforms is stored.”
The worst of the vulnerabilities discovered have a severity level of 9.5 in important applications such as SAP SQL Anywhere and Sybase ESP.
“We are not only talking about the number of vulnerabilities, which is quite large, but also about the criticality,” says ERPScan founder Alexander Polyakov.
Polyakov reports:
“If experienced SAP developers can still leave such errors in their code, imagine what happens to SAP custom programs, especially those outsourced to other companies. Intense competition among outsourcing companies leads to minimizing development time and resources, which usually has security implications.”
Polyakov has published whitepapers detailing SAP vulnerabilities, penetration testing guidelines, and defenses.
View the whitepapers

