Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

SAP Security email sent out to CIO's

Former Member
0 Kudos

Have any of you seen or acted on the flag that SAP AG has sent out to all CIO's of organizations warning to immediately implement the following 5 security OSS notes?:

"Please pay immediate attention to the following security-related service notes, which SAP considers to be especially critical for your systems.

Note 1298160 - Security note: Forbidden program execution possible

Note 1168813 - Security Note: Program DISPLAY_FUNC_INCLUDE

Note 1167258 - Security Note: Program RS_REPAIR_SOURCE

Note 1304803 - Security note: Changing a transport without authorization "

I would like to bounce a few questions out to those of you who are familiar, and what type of ongoing "continuous monitoring" strategy you currently work with.

Thanks in advance!

Howard Mason

4 REPLIES 4

Former Member
0 Kudos

My apologies, 4 OSS notes.

HM

0 Kudos

Hi Howard,

These notes were a bit of a speciality in that SAP owned up to them and made every customer aware of them by the custom mailshots and the link on the first page of SAP service marketplace. Having said that there are a couple of really serious ones that we've discussed in recent threads you may have seen.

I periodically check the HotNews and TopNotes links that are in the spotlight news, but that does require a bit of reading up to see if notes are relevant. Fortunately my job description covers this sort of research and my line manager supports the time this takes.

Once I've found a note that could be of interest I have an excellent ABAP aware security analyst who can help with the testing of the notes to see if these could impact any of our 34 production SAP instances (you name it we run it on SAP). My ABAP is too rusty to do this myself, so in a process you'd need someone with such skills to be able to understand any program specific issues.

Finally we run these past our infrastructure guys to make sure we are right with our concerns, as this alerts them to the notes that we might be getting them to apply for us.Again my Basis knowledge is quite old, so it makes sense to involve the experts in assessing if something really is a risk.

We are looking to expand such an approach to cover functional notes, particularly as we are aware some notes might be being looked at by security, basis, development and functional teams through out our organisation. By having a forum we might be able to save effort by one area passing notes of interest to other subject matter experts in other teams.

Hope this gives some insight into one approach, if anyone else out there has a better way of doing this we can all learn.

Regards,

Chris H.

PS > we have applied all of these notes, without any issues to date.

Edited by: Chris Haigh on Apr 17, 2009 6:19 PM

0 Kudos

Thanks Chris

Good weekend!

Cheers,]

Howard

Former Member
0 Kudos

Thanks Chris, and I have searched, and will in the future, for prior mention on existing postings on the same.