Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

SAP Patch Tuesday: August Security Updates & Breach Insights

Onapsis
05/08/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


ERP security. And it's an interesting time because it's a change of seasons, right? In some parts of the world, we're coming to the end of summer, in some parts of the world, we're coming to the end of winter. So we'd like to welcome you here as we kick off our August edition. It's again, if you're not aware, JP and I both come together to talk about ERP security. So let's go ahead and kick it off, JP. Absolutely. Thank you, Paul. And actually, I was thinking while you were speaking, and we are in opposite seasons, right? And we typically go in the opposite direction. But it's always good when we have these seasons changing. In some places getting colder, some places getting warmer. Absolutely. I'm hot and you're wearing a sweatshirt. Yeah. But we all share, even though we are in opposite seasons, we all share the same passion for ERP security. So let's go into Patch Tuesday for SAP. We are in August Patch Tuesday here. We're going to cover the summary of the 25 new and updated SAP security nodes coming in August, including two hot news and four high priority nodes. I'm very happy to share that almost 25% of the nodes that were released by SAP fixing security vulnerabilities were fixing vulnerabilities reported by the Onapsis Research Labs. So it's always good to see this significant contribution by this team of professional researchers that know so much about the technology that supports SAP applications. But I also wanted to cover two special nodes that are these hot news. SAP security node 3479478 with a CVSS of 9.8. This is a vulnerability affecting SAP business objects. There was a lot of media attention from this vulnerability because of the high CVSS and the criticality because an attacker can fully compromise the system in impacting confidentiality, integrity and availability. So if you're running business objects, go ahead and patch this vulnerability, upgrade the system on the security node. And the second one is SAP security node 3477196. This one holds a CVSS score of 9.1 and it affects the Node.js library. But if you think about SAP technology, wait a minute, where is Node.js in the SAP technology stack? Well, it's in a couple of places. One of them is when you deploy a new application using SAP build apps. So if you create a new app using SAP build apps and you deploy it with Node.js versions prior to 4.11.130, then that application is vulnerable to this CV202429415. So go ahead and take a look at your applications. Make sure that if you have deployed applications with Node.js, you need to rebuild them and redeploy these applications, including the newest version of Node.js, or at least the one which is not vulnerable to this CV202429415. So that's it in terms of the summary of the SAP security nodes for August. Back to you, Paul. Thanks, JP. Well, as with the change of seasons, there's also this continual situation that we have with data breaches. And the data breaches include all sorts of companies, all sorts of websites. This newest one is from National Public Data, and it is concerning a social security breach here in the United States. It's a pretty large one, and it's also indicative of a larger challenge with security breaches. So this breach was done a few months ago, and it was initially put on the market for $3.5 million. It contains social security data, along with names, addresses, telephone numbers. It's now available for free, but there's some information that's not included with it, like telephone numbers, for instance. It's always a challenge, right? You have your data with these companies, companies like this one that are generally used for employers, doing background checks on prospective employees, as well as other criteria. So your information is just shared. It's used for purposes, for things like, again, getting hired. But it's these companies that we don't know, and we don't know what their security posture is. So if you're having data, right, the most important thing is to follow the cybersecurity framework, right? And this publishes it. You want to go ahead and set up the right technology stacks. You want to have the right professionals, the training, the right programs. You want to monitor. You want to make sure that you're patching. These are all so very important to a security lifecycle. But if your data is breached and stolen, because it happens, right, today's technology stacks are complex between cloud and on-prem, with all the different laptops and ways to access that data, one hole can be devastating. But as a person that might be impacted by this as a consumer or as a victim, your options are basically to go and make sure that you put alerts on your credit profile. You put alerts on your credit cards. You put alerts on your digital profile to make sure that your profile is being protected. The last thing that you want to find happening is that your information is being used to submit fraudulent IRS tax forms. So probably best bet to go to the IRS and make sure that you have protections there. It's a whole compendium of things that you should probably take a look at to protect your digital identity. But this underscores that we are one big system in this digital space, right? One impact somewhere can have an impact on us elsewhere. So it is up to all of us to be accountable for our own digital footprint and to make sure that our own digital profile is protected, much in like the same way when you're driving a car, right? We have rules, we have laws, and when we go out there, we not only drive, but we have to be defensive drivers as well. We have to stay a certain length behind cars. We have to, you know, look in our blind spots to make sure that when we're turning into lanes, we're not hitting somebody or someone's going to hit us. It's the same right in the digital landscape. We need to also have a good security curation of our digital profiles. So just something to be aware of, check to make sure that you have those security precautions in place. JP, handing it back over to you. Thank you, Paul. And I wanted to share a couple of additional items for today's or this month's Defenders Digest. One of them being a recent zero-day vulnerability that was shared from researchers from the company Oligo Security, that they found a way of exploiting browsers, bypassing certain protections. And this includes major web browsers, Safari, Chrome, Firefox. By sending requests to a specific address, and that specific address being 0.0.0.0, this allows attackers to bypass specific protections and gain unauthorized access to resources that are locally available. So there is another option to go ahead and update your browsers. That's a fundamental security rule that we need to stay on top of the latest vulnerabilities, but stay on top of the latest updates for browsers, right? You shouldn't be browsing the internet with an outdated browser, because we know that there are sites that will potentially incorporate the exploitation of vulnerabilities if those browsers are not up to date. So it's possible to mitigate this by disabling JavaScript, but I don't know how many of you can actually browse the internet without JavaScript today. It's almost granted for the majority of websites that we navigate in. So it's very, very important to keep our browsers up to date. And I wanted to also share with you some of the latest results from SAP. When we think about SAP security, the importance of SAP applications, we're always talking about that with Paul, and from the Onapsis perspective, hey, some of the biggest organizations that run our lives, that provide for the energy, the food, the healthcare, pretty much everything, these organizations run their business processes through SAP. So they operate depending on SAP up and running, and most of them would not be able to operate if those systems are down. And that footprint continues to grow, right? SAP is not reducing their customer base. It's actually increasing. Just to share a couple of examples with you, the cloud backlog went up 28% on the last quarter. Cloud revenue up 25%. Customer revenue up 10% considering everything cloud and on cloud. So it continues to grow, and the revenue is a proxy to understanding the new customers, the new implementations, the new deployments. So the surface of SAP applications continues to grow, and these are very, very critical for everyone, right? For us as well, because we depend in many different ways of SAP customers to be up and running for the things that we do day in, day out. So just a thought to give you, to keep on the back of our heads, SAP applications are critical. They continue growing in terms of the technology and the number of customers. So it's important to continue putting security front and center for these applications. And with that, Paul, back to you to wrap up. Yeah, thanks for sharing those key two results for SAP and the results that they post. I mean, that just goes to speak to how important it is for companies to have good controls on financial reporting. So when we see those numbers, I mean, SAP is doing amazing. Let's finish up. This week, we're doing a webinar on a C2 botnet research that we had done. And it kind of is a follow on from the Chatter report. So the Chatter report was this higher level business conversation about what was happening in the underground and the interest in SAP. This C2 botnet webinar that we're conducting on Wednesday this week, if you can join us, great. If you joined us, fantastic. I'm not sure when this is playing. But this is a technical dive into what we've observed in an attack in our space. So if you've joined us, or if you can join us, please do. It's going to be fascinating. We look forward to seeing you there. If you have any questions about it, please go ahead and contact us. Thank you once again for joining us. JP, as always, fantastic and looking forward to seeing you in a month. Thank you all. Yeah, this is me at the beach. Yeah.

TL;DR

  • SAP's August Patch Tuesday includes 25 security notes with two critical hot news items: a CVSS 9.8 Business Objects vulnerability requiring immediate patching and a CVSS 9.1 Node.js vulnerability affecting SAP Build Apps that requires rebuilding and redeploying applications.
  • The National Public Data breach exposed social security numbers and personal information of millions, now freely available after initially being sold for $3.5 million, highlighting the need for proactive credit monitoring and digital identity protection measures.
  • A zero-day browser vulnerability affecting Safari, Chrome, and Firefox allows attackers to bypass protections via 0.0.0.0 requests, emphasizing the critical importance of keeping browsers updated as JavaScript disabling is not practical for modern web use.
  • SAP's continued growth with 28% cloud backlog increase and 25% cloud revenue growth demonstrates the expanding attack surface of critical business applications that power essential infrastructure across multiple industries.
  • Onapsis Research Labs contributed to nearly 25% of the vulnerabilities fixed in SAP's August release, showcasing their significant role in identifying and reporting security issues in the SAP ecosystem.

August SAP Security Updates and Critical Vulnerabilities

This episode covers SAP's August Patch Tuesday release, which includes 25 new and updated security notes addressing vulnerabilities across the SAP technology stack. Two hot news items stand out: a critical SAP Business Objects vulnerability (CVE with CVSS 9.8) that allows full system compromise, and a Node.js library vulnerability (CVSS 9.1) affecting SAP Build Apps deployments. Organizations running these technologies need immediate patching and, in the case of Build Apps, must rebuild and redeploy applications with updated Node.js versions. Notably, Onapsis Research Labs contributed to nearly 25% of the vulnerabilities fixed in this release, demonstrating their deep expertise in SAP security research.

National Public Data Breach and Digital Identity Protection

The discussion addresses a significant data breach at National Public Data, a background check provider, which exposed social security numbers, names, addresses, and other personal information. Initially offered for sale at $3.5 million, the data is now freely available. This breach highlights the broader challenge of data security across third-party vendors that consumers have no direct relationship with but whose services are used by employers and other organizations. The episode emphasizes the importance of defensive measures including credit monitoring, fraud alerts, IRS identity protection, and maintaining awareness of one's digital footprint across the interconnected digital ecosystem.

Browser Zero-Day and SAP's Continued Market Growth

The episode covers a zero-day vulnerability discovered by Oligo Security affecting major browsers (Safari, Chrome, Firefox) that allows attackers to bypass protections by sending requests to 0.0.0.0, potentially gaining unauthorized access to local resources. The primary mitigation is keeping browsers updated, as disabling JavaScript is impractical for modern web browsing. Additionally, SAP's latest quarterly results show significant growth with cloud backlog up 28%, cloud revenue up 25%, and overall customer revenue up 10%, indicating the expanding attack surface of SAP applications and reinforcing the critical importance of securing these systems that power essential infrastructure across energy, food, healthcare, and other vital sectors.

Chapters

0:00 - Introduction and Welcome
1:23 - SAP August Patch Tuesday Overview
2:20 - Critical Business Objects Vulnerability
3:04 - Node.js Vulnerability in SAP Build Apps
4:24 - National Public Data Breach Discussion
8:35 - Browser Zero-Day Vulnerability
10:28 - SAP Financial Results and Growth
13:10 - Upcoming C2 Botnet Webinar

Key Quotes

1:52 "Almost 25% of the nodes that were released by SAP fixing security vulnerabilities were fixing vulnerabilities reported by the Onapsis Research Labs."
2:32 "This is a vulnerability affecting SAP business objects. There was a lot of media attention from this vulnerability because of the high CVSS and the criticality because an attacker can fully compromise the system in impacting confidentiality, integrity and availability."
7:40 "We are one big system in this digital space, right? One impact somewhere can have an impact on us elsewhere."
11:03 "They operate depending on SAP up and running, and most of them would not be able to operate if those systems are down."
11:34 "The cloud backlog went up 28% on the last quarter. Cloud revenue up 25%. Customer revenue up 10% considering everything cloud and on cloud."

Categories:
  • » Cybersecurity » Data Security
  • » Cybersecurity » Application Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Application Security
  • Data Privacy
  • Vulnerability Management
  • Threat Intelligence
  • Technical Deep Dive
  • SAP Security Patches
  • Patch Tuesday
  • Business Objects Vulnerabilities
  • Node.js Security
  • Data Breaches
  • Social Security Number Theft
  • Browser Security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: SAP Patch Tuesday: August Security Updates & Breach Insights

              Upcoming Webinar Calendar

              • 06/23/2026
                01:00 PM
                06/23/2026
                The AI-Powered VMware Alternative
                https://www.truthinit.com/index.php/channel/2009/the-ai-powered-vmware-alternative/
              • 06/24/2026
                11:00 AM
                06/24/2026
                Accelerating Through AI: A Dynamic Webinar Series
                https://www.truthinit.com/index.php/channel/2012/accelerating-through-ai-a-dynamic-webinar-series/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 06/30/2026
                01:00 PM
                06/30/2026
                Mastering Active Directory Certificate Services for Long-Term Success
                https://www.truthinit.com/index.php/channel/2018/mastering-active-directory-certificate-services-for-long-term-success/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Integrating Security in AI: Automated Red Teaming Strategies for Private Models
                https://www.truthinit.com/index.php/channel/1969/integrating-security-in-ai-automated-red-teaming-strategies-for-private-models/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/01/2026
                01:00 PM
                07/01/2026
                Preventing Your AI from Turning Against You: Essential Strategies
                https://www.truthinit.com/index.php/channel/2021/preventing-your-ai-from-turning-against-you-essential-strategies/
              • 07/02/2026
                10:00 AM
                07/02/2026
                When the cloud goes dark: Resilience lessons from hybrid threats
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/
              • 07/07/2026
                01:00 PM
                07/07/2026
                A Comprehensive Demonstration of DLP Solutions and Strategies
                https://www.truthinit.com/index.php/channel/2030/a-comprehensive-demonstration-of-dlp-solutions-and-strategies/
              • 07/09/2026
                01:00 PM
                07/09/2026
                The HUMAN Experience: Empowering Trust Through Action and Engagement
                https://www.truthinit.com/index.php/channel/2026/the-human-experience-empowering-trust-through-action-and-engagement/
              • 07/14/2026
                01:00 PM
                07/14/2026
                Crafting a Championship-Quality Security Team for Unmatched Defense
                https://www.truthinit.com/index.php/channel/2025/crafting-a-championship-quality-security-team-for-unmatched-defense/
              • 07/21/2026
                04:00 AM
                07/21/2026
                Strategies for Managing AI Governance and Securing App-to-LLM API Traffic
                https://www.truthinit.com/index.php/channel/1967/strategies-for-managing-ai-governance-and-securing-app-to-llm-api-traffic/
              • 07/21/2026
                01:00 PM
                07/21/2026
                HUMAN Dialogue: Insights from Attackers Revealed at the FIFA World Cup
                https://www.truthinit.com/index.php/channel/2029/human-dialogue-insights-from-attackers-revealed-at-the-fifa-world-cup/
              • 07/22/2026
                06:30 AM
                07/22/2026
                Understanding the Dynamics of Data Privacy and Protection Regulations
                https://www.truthinit.com/index.php/channel/2000/understanding-the-dynamics-of-data-privacy-and-protection-regulations/
              • 07/28/2026
                01:00 PM
                07/28/2026
                Illumio + Netskope: Zero Trust in the Age of AI Autonomy
                https://www.truthinit.com/index.php/channel/2031/illumio-netskope-zero-trust-in-the-age-of-ai-autonomy/
              • 07/29/2026
                04:00 AM
                07/29/2026
                Real-Time Strategies for Safeguarding Against Prompt Injections
                https://www.truthinit.com/index.php/channel/1968/real-time-strategies-for-safeguarding-against-prompt-injections/
              • 09/30/2026
                04:00 AM
                09/30/2026
                AI Command Center: Optimizing Visibility and Control in Your Operations
                https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/

              Upcoming Events

              • Jun
                23

                The AI-Powered VMware Alternative

                06/23/202601:00 PM ET
                • Jun
                  24

                  Accelerating Through AI: A Dynamic Webinar Series

                  06/24/202611:00 AM ET
                  • Jun
                    25

                    Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                    06/25/202601:00 PM ET
                    • Jun
                      30

                      Mastering Active Directory Certificate Services for Long-Term Success

                      06/30/202601:00 PM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version