Disclosure Guidelines for SAP Security Advisories

Disclosure Guidelines for security advisories reported to SAP from external resources. Pobierz dokument

© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to SAP Materials for general audiences.PUBLICDisclosure Guidelines for SAP Security Advisories02-APRIL-2026
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to SAP Materials for general audiences.SAP SECURITY RESPONSE AND REPORTING VULNERABILITIESSince the integrity and security of business operations is crucial for businesses in all industries, SAP as aprovider of business software is absolutely committed to maintaining the security of its products and services.SAP takes the security of its products very seriously, with a comprehensive Secure Software Development Life-cycle process, and a dedicated Security Response process in place as the most visible evidence of itscommitment.The SAP Security Response team is responsible for investigating all reported security vulnerabilities, workingclosely with reporters of vulnerabilities and SAP product development to address those vulnerabilities, andinforming customers about how to incorporate the remediation for those vulnerabilities through SecurityNotes with their associated patches to fully keep their operations secure.Vulnerabilities in current or former product versions should be reported to the Security Response Team bycompleting and submitting the report form on the SAP Trust Center site:https://www.sap.com/about/trust-center/security/incident-management.html(direct link: https://vulnerability-form.cfapps.sap.hana.ondemand.com)This is preferred over a direct email submission since the form specifies the Information the team needs toevaluate and address the reported issue and encrypts the submission and associated attachments so that theyare all transmitted securely.SAP COORDINATED VULNERABILITY DISCLOSURESAP appreciates the submission of vulnerability information, but our principal concern must be the security andintegrity of our customers and their business processes and practices. Therefore, SAP uses a CoordinatedVulnerability Disclosure process to ensure that vulnerabilities and their associated effects are kept confidentialuntil remediations are available and customers have had ample opportunity to incorporate them.The process for fixing security vulnerabilities can be long and arduous. When a vulnerability is reported aCoordinator (or Case Owner) will be assigned to coordinate communications between the reporter and theteams involved in addressing the remediation and publishing the results. With the reporter’s permission, thepublication of results will normally include credits for finding and reported vulnerability. The Security Responseteam will not provide acknowledgements if the researcher has disclosed the issue before the fix has beenreleased.
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to SAP Materials for general audiences.AVOIDING PREMATURE DISCLOSURE OF VULNERABILITIESSAP is eager to credit the researchers and reporters of security vulnerabilities, but it is important to givecustomers ample time and opportunity to incorporate fixes/patches into their vulnerable systems.The deployment of patches for SAP enterprise systems is usually more complicated than a software upgrade ona consumer PC. Depending on the nature and complexity of the vulnerability, the deployment of patches mayrequire manual configuration and/or “downtime” as well as an automated update. Due to these additionalcomplications, some of our customers have regular patching cycles, for instance on a monthly or a quarterlybasis.Considering these circumstances, SAP requests that security researchers provide sufficient time for customersto implement patches in their SAP systems. As a rule of thumb, SAP suggests respecting an implementationtime of three months once the patch is released and asks all security researchers to not disseminate any kindof information or tools that would serve to exploit the vulnerability during that time. Please inform the SecurityResponse team about planned publications, public advisories and external presentations which disseminateSAP product security content.PUBLICATIONS, TALKS AND CONFERENCE PRESENTATIONSFor these reasons, SAP requests all security researchers to inform the Security Response team via encryptedemail [secure@sap.com (Link to the public key)] about all planned talks at security conferences or papers insecurity publications.SAP further requests researchers intending presentations or publications which include SAP product securitycontent to: Provide the planned content, even a draft version - this could be in parallel with the “call for papersreply. Send each presentation with SAP product security content at least 3 weeks before the talk isscheduled. Disclose only issues where the relevant Security Note has been released at least three months prior special care should be taken that no Zero Days are disclosed. The information presented should not contain exploits or Proofs of Concept (PoC). The content should mention the relevant Security Note(s) and/or the corresponding SAPdocumentation for each disclosed issue.SAP appreciates that researchers want to take credit for their work which includes the publication andpresentation of their findings. These guidelines are provided so that SAP can give technical feedback to ensurecorrectness and to avoid placing SAP customers at unnecessary risk through premature disclosure orinsufficient information to protect their systems.