Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs

SAP Security Patch Analysis & Ransomware Threat Update

Onapsis
03/26/2026
0
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


TL;DR

  • SAP's March Patch Tuesday addressed 12 security notes including a critical code injection vulnerability (CVSS 9.1) in NetWeaver Java's log viewer and a library vulnerability (CVSS 9.4) affecting SAP Build Apps requiring application rebuilds
  • Organizations running SAP NetWeaver Java should prioritize patching three critical vulnerabilities, with Onapsis Research Labs contributing to the discovery of three information disclosure issues in this release
  • A sophisticated phishing campaign exploited an open redirect vulnerability in SAP to bypass security filters by using legitimate domain names, demonstrating the importance of vulnerability management and user awareness
  • Major ransomware groups Alpha V/Black Cat and LockBit have faced disruption, with LockBit's infrastructure seized by law enforcement after extorting $120 million from over 2,000 victims, while CISA continues issuing alerts about active campaigns

March Patch Tuesday Critical Findings

This episode provides detailed analysis of SAP's March Patch Tuesday release, which included 12 new and updated security notes with three hot news and three high-priority vulnerabilities. The most critical issue is a code injection vulnerability in SAP NetWeaver Java's log viewer (CVE 9.1), which failed to properly restrict file uploads, allowing attackers to upload dangerous file types and potentially execute commands on the operating system. Another critical vulnerability affects SAP Build Apps (CVE 9.4), requiring organizations to rebuild all applications created with versions lower than 4.9.145 due to a vulnerable library. The Onapsis Research Labs contributed to discovering three information disclosure vulnerabilities in this release, continuing their collaboration with SAP on vulnerability research.

Open Redirect Phishing Tactics and Ransomware Updates

The discussion covers a sophisticated phishing campaign targeting a large multinational SAP customer using an open redirect vulnerability. This attack vector allows threat actors to leverage legitimate domain names in phishing emails, bypassing security filters by appending malicious redirect parameters to trusted URLs. The episode also provides updates on major ransomware operations, including Alpha V/Black Cat's alleged shutdown after receiving tens of millions in ransom payments, and LockBit's disruption following FBI and UK NCA seizure of their infrastructure after the group extorted approximately $120 million from over 2,000 victims worldwide. CISA has released alerts about ongoing ransomware campaigns that organizations should monitor closely.

Chapters

0:00 - Introduction
0:31 - March Patch Tuesday Overview
1:39 - Critical SAP Build Apps Vulnerability
2:58 - NetWeaver Java Log Viewer Issue
4:01 - High Priority Patches
5:48 - Open Redirect Phishing Campaign
10:40 - Ransomware Group Updates
12:38 - SAP Penetration Testing Training
14:35 - Closing Remarks
15:16 - Outtakes

Key Quotes

1:00 "It's important to note that there's been a focus on SAP NetWeaver Java because there's been a critical note affecting SAP NetWeaver Java and three information disclosure ones."
2:26 "Fixing this is somehow straightforward, but also not straightforward, because it's really upgrading the version of the library. But you need to go back and rebuild all of those affected applications."
3:27 "An attacker was able to upload sensitive or let's say dangerous file types. Now the patch, if you upgrade the plugin, the log viewer plugin, basically it's restricting the file types to only the ones that are not dangerous."
9:07 "An attacker can say, hey, I'm your IT department, right? I need you to log in. And then they'll send you an email with a totally legit, valid domain. That domain is not going to get picked up by your filters because it's scored as legitimate."
12:52 "I have no question or no hesitation in saying that we have the industry-leading team in terms of experience, in terms of tools, in terms of background to perform SAP pentests."
Categories:
  • » Cybersecurity » Application Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Application Security
  • Vulnerability Management
  • Threat Intelligence
  • Technical Deep Dive
  • Best Practices
  • SAP Security Patches
  • SAP NetWeaver Java
  • Code Injection Vulnerabilities
  • Phishing Attacks
  • Open Redirect Exploits
  • Ransomware Operations
  • Penetration Testing
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: SAP Security Patch Analysis & Ransomware Threat Update

              Upcoming Webinar Calendar

              • 04/08/2026
                01:00 PM
                04/08/2026
                Managing Configuration at Scale Across Group Policy and Intune
                https://www.truthinit.com/index.php/channel/1865/managing-configuration-at-scale-across-group-policy-and-intune/
              • 04/15/2026
                01:00 PM
                04/15/2026
                Service Account Security in the Age of AI: From Legacy Accounts to Agentic Identities
                https://www.truthinit.com/index.php/channel/1866/service-account-security-in-the-age-of-ai-from-legacy-accounts-to-agentic-identities/
              • 04/30/2026
                10:00 AM
                04/30/2026
                Insights from the 2026 Keepit Annual Data Report on SaaS Data Protection
                https://www.truthinit.com/index.php/channel/1868/insights-from-the-2026-keepit-annual-data-report-on-saas-data-protection/

              Upcoming Events

              • Apr
                08

                Managing Configuration at Scale Across Group Policy and Intune

                04/08/202601:00 PM ET
                • Apr
                  15

                  Service Account Security in the Age of AI: From Legacy Accounts to Agentic Identities

                  04/15/202601:00 PM ET
                  • Apr
                    30

                    Insights from the 2026 Keepit Annual Data Report on SaaS Data Protection

                    04/30/202610:00 AM ET
                    More events
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version