SAP Basis Basics Part 36
SAP Security Patch Day
The security maintenance of installed SAP software is key to continuously protect also against new types of attacks or newly identified potential weaknesses.
Based on feedback from customers, partners and SAP user groups, SAP has launched a regular SAP Security Patch Day, scheduled for the second Tuesday of every month — which has been synchronized with the Security Patch Day of other major software vendors.
On these SAP Patch Days, SAP publishes software corrections as SAP Security Notes, focused solely on security to protect against potential weaknesses or attacks. Access SAP Security Notes (https://lnkd.in/errd6d8c) in SAP for Me, then select All Security Notes, to get the complete list of all SAP Security Notes. We recommend that you implement these corrections at a priority. Several tools are available to help identify, select and implement these corrections.
SAP categorizes SAP Security Notes as Patch Day Security Notes and Support Package Security Notes, with the sole purpose of making you focus on important fixes on patch days and the rest to be implemented automatically during SP upgrades. For details refer to the SAP Security Notes FAQ (https://lnkd.in/e4wzxrbR). Security fixes for SAP NetWeaver based products are also delivered with the support packages.
Starting June 11, 2019, for all new SAP Security Notes with high or very high severity we deliver fix for Support Packages shipped within the last 24 months* for the versions under Mainstream Maintenance and Extended Maintenance. This is extended from the previous Support Package coverage of 18 months.
Notes with low or medium priority contain corrections in at least the newest support package in all mainstream and extended maintenance releases.
*For information on areas with an exception from the 24 months maintenance strategy, refer to the SAP Security Notes FAQ.
SAP Security Notes & News:
https://support.sap.com/en/my-support/knowledge-base/security-notes-news.html
SAP Security Notes in SAP for Me:
https://me.sap.com/app/securitynotes
SAP Security Notes FAQ:
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/security-notes-faqs.html
As Example, Security Notes from july with a CVSS Score greater than 7 (All High and Very High (Hotnews)) Security Notes: