SAP Updates Two-Year-Old Patch for TREX Vulnerability

SAP has issued an updated patch for a code-injection vulnerability affecting the TREX search engine integrated into more than a dozen SAP products. Continue reading SAP Updates Two-Year-Old Patch for TREX Vulnerability

SAP Vulnerability Puts Business Data at Risk for Thousands of Companies

Researchers at ERPScan today disclosed details and a proof-of-concept exploit for a SAP GUI remote code execution vulnerability patched last week. Continue reading SAP Vulnerability Puts Business Data at Risk for Thousands of Companies

Attackers Targeting Critical SAP Flaw Since 2013

Researchers at Onapsis and DHS CERT today published reports describing a critical SAP Invoker Servlet vulnerability that has been used to attack 36 global enterprises spanning 15 critical industries. Continue reading Attackers Targeting Critical SAP Flaw Since 2013