SAP: It takes exploit devs 72 hours to turn our security patches into a weapon(theregister.com)
theregister.com
SAP: It takes exploit devs 72 hours to turn our security patches into a weapon
https://www.theregister.com/2021/04/06/sap_patch_attacks/
5 comments
What is sap even written in? Never used it. If it’s a cloud app, why do sysadmins need to manually install patches? Wouldn’t this be pushed by sap themselves?
SAP ERP is nowadays mostly written in C(++), java and ABAP (their own programming language to implement business logic, forms and reports) with SAP HANA bringing Web technologies.
SAP also predates the cloud, it used to be in mainframe land though (SAP R/2).
It has a cloud offering in its latest revision SAP HANA, but switching a major version is prohibitely expensive and requires immense amounts of work.
SAP also predates the cloud, it used to be in mainframe land though (SAP R/2).
It has a cloud offering in its latest revision SAP HANA, but switching a major version is prohibitely expensive and requires immense amounts of work.
And what percentage of system administrators apply all patches within 72 hours of release? I'd be very surprised if it was higher than single digits.
This is really scary but hardly surprising!
Yet more pressure to move to SaaS (which is probably why SAP are happy to disclose this).
Obligatory SAP is terrible. I wouldn't wish it on my worst enemy
SAP is a magic money tree for those that know it well.
I don't want to become rich off of other people's suffering