Disclosure Guidelines for SAP Security Advisories
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to SAP Materials for general audiences.
SAP SECURITY RESPONSE AND REPORTING VULNERABILITIES
Since the integrity and security of business operations is crucial for businesses in all industries, SAP as a
provider of business software is absolutely committed to maintaining the security of its products and services.
SAP takes the security of its products very seriously, with a comprehensive Secure Software Development Life-
cycle process, and a dedicated Security Response process in place as the most visible evidence of its
commitment.
The SAP Security Response team is responsible for investigating all reported security vulnerabilities, working
closely with reporters of vulnerabilities and SAP product development to address those vulnerabilities, and
informing customers about how to incorporate the remediation for those vulnerabilities through Security
Notes with their associated patches to fully keep their operations secure.
Vulnerabilities in current or former product versions should be reported to the Security Response Team by
completing and submitting the report form on the SAP Trust Center site:
https://www.sap.com/about/trust-center/security/incident-management.html
(direct link: https://vulnerability-form.cfapps.sap.hana.ondemand.com)
This is preferred over a direct email submission since the form specifies the Information the team needs to
evaluate and address the reported issue and encrypts the submission and associated attachments so that they
are all transmitted securely.
SAP COORDINATED VULNERABILITY DISCLOSURE
SAP appreciates the submission of vulnerability information, but our principal concern must be the security and
integrity of our customers and their business processes and practices. Therefore, SAP uses a Coordinated
Vulnerability Disclosure process to ensure that vulnerabilities and their associated effects are kept confidential
until remediations are available and customers have had ample opportunity to incorporate them.
The process for fixing security vulnerabilities can be long and arduous. When a vulnerability is reported a
Coordinator (or Case Owner) will be assigned to coordinate communications between the reporter and the
teams involved in addressing the remediation and publishing the results. With the reporter’s permission, the
publication of results will normally include credits for finding and reported vulnerability. The Security Response
team will not provide acknowledgements if the researcher has disclosed the issue before the fix has been
released.
SAP SECURITY RESPONSE AND REPORTING VULNERABILITIES
Since the integrity and security of business operations is crucial for businesses in all industries, SAP as a
provider of business software is absolutely committed to maintaining the security of its products and services.
SAP takes the security of its products very seriously, with a comprehensive Secure Software Development Life-
cycle process, and a dedicated Security Response process in place as the most visible evidence of its
commitment.
The SAP Security Response team is responsible for investigating all reported security vulnerabilities, working
closely with reporters of vulnerabilities and SAP product development to address those vulnerabilities, and
informing customers about how to incorporate the remediation for those vulnerabilities through Security
Notes with their associated patches to fully keep their operations secure.
Vulnerabilities in current or former product versions should be reported to the Security Response Team by
completing and submitting the report form on the SAP Trust Center site:
https://www.sap.com/about/trust-center/security/incident-management.html
(direct link: https://vulnerability-form.cfapps.sap.hana.ondemand.com)
This is preferred over a direct email submission since the form specifies the Information the team needs to
evaluate and address the reported issue and encrypts the submission and associated attachments so that they
are all transmitted securely.
SAP COORDINATED VULNERABILITY DISCLOSURE
SAP appreciates the submission of vulnerability information, but our principal concern must be the security and
integrity of our customers and their business processes and practices. Therefore, SAP uses a Coordinated
Vulnerability Disclosure process to ensure that vulnerabilities and their associated effects are kept confidential
until remediations are available and customers have had ample opportunity to incorporate them.
The process for fixing security vulnerabilities can be long and arduous. When a vulnerability is reported a
Coordinator (or Case Owner) will be assigned to coordinate communications between the reporter and the
teams involved in addressing the remediation and publishing the results. With the reporter’s permission, the
publication of results will normally include credits for finding and reported vulnerability. The Security Response
team will not provide acknowledgements if the researcher has disclosed the issue before the fix has been
released.
© 2026 SAP SE or an SAP affiliate company. All rights reserved. See Legal Notice on www.sap.com/legal-notice for use terms, disclaimers, disclosures, or restrictions related to SAP Materials for general audiences.
AVOIDING PREMATURE DISCLOSURE OF VULNERABILITIES
SAP is eager to credit the researchers and reporters of security vulnerabilities, but it is important to give
customers ample time and opportunity to incorporate fixes/patches into their vulnerable systems.
The deployment of patches for SAP enterprise systems is usually more complicated than a software upgrade on
a consumer PC. Depending on the nature and complexity of the vulnerability, the deployment of patches may
require manual configuration and/or “downtime” as well as an automated update. Due to these additional
complications, some of our customers have regular patching cycles, for instance on a monthly or a quarterly
basis.
Considering these circumstances, SAP requests that security researchers provide sufficient time for customers
to implement patches in their SAP systems. As a rule of thumb, SAP suggests respecting an implementation
time of three months once the patch is released and asks all security researchers to not disseminate any kind
of information or tools that would serve to exploit the vulnerability during that time. Please inform the Security
Response team about planned publications, public advisories and external presentations which disseminate
SAP product security content.
PUBLICATIONS, TALKS AND CONFERENCE PRESENTATIONS
For these reasons, SAP requests all security researchers to inform the Security Response team via encrypted
email [secure@sap.com (Link to the public key)] about all planned talks at security conferences or papers in
security publications.
SAP further requests researchers intending presentations or publications which include SAP product security
content to:
• Provide the planned content, even a draft version - this could be in parallel with the “call for papers”
reply.
• Send each presentation with SAP product security content at least 3 weeks before the talk is
scheduled.
• Disclose only issues where the relevant Security Note has been released at least three months prior –
special care should be taken that no Zero Days are disclosed.
• The information presented should not contain exploits or Proofs of Concept (PoC).
• The content should mention the relevant Security Note(s) and/or the corresponding SAP
documentation for each disclosed issue.
SAP appreciates that researchers want to take credit for their work which includes the publication and
presentation of their findings. These guidelines are provided so that SAP can give technical feedback to ensure
correctness and to avoid placing SAP customers at unnecessary risk through premature disclosure or
insufficient information to protect their systems.
AVOIDING PREMATURE DISCLOSURE OF VULNERABILITIES
SAP is eager to credit the researchers and reporters of security vulnerabilities, but it is important to give
customers ample time and opportunity to incorporate fixes/patches into their vulnerable systems.
The deployment of patches for SAP enterprise systems is usually more complicated than a software upgrade on
a consumer PC. Depending on the nature and complexity of the vulnerability, the deployment of patches may
require manual configuration and/or “downtime” as well as an automated update. Due to these additional
complications, some of our customers have regular patching cycles, for instance on a monthly or a quarterly
basis.
Considering these circumstances, SAP requests that security researchers provide sufficient time for customers
to implement patches in their SAP systems. As a rule of thumb, SAP suggests respecting an implementation
time of three months once the patch is released and asks all security researchers to not disseminate any kind
of information or tools that would serve to exploit the vulnerability during that time. Please inform the Security
Response team about planned publications, public advisories and external presentations which disseminate
SAP product security content.
PUBLICATIONS, TALKS AND CONFERENCE PRESENTATIONS
For these reasons, SAP requests all security researchers to inform the Security Response team via encrypted
email [secure@sap.com (Link to the public key)] about all planned talks at security conferences or papers in
security publications.
SAP further requests researchers intending presentations or publications which include SAP product security
content to:
• Provide the planned content, even a draft version - this could be in parallel with the “call for papers”
reply.
• Send each presentation with SAP product security content at least 3 weeks before the talk is
scheduled.
• Disclose only issues where the relevant Security Note has been released at least three months prior –
special care should be taken that no Zero Days are disclosed.
• The information presented should not contain exploits or Proofs of Concept (PoC).
• The content should mention the relevant Security Note(s) and/or the corresponding SAP
documentation for each disclosed issue.
SAP appreciates that researchers want to take credit for their work which includes the publication and
presentation of their findings. These guidelines are provided so that SAP can give technical feedback to ensure
correctness and to avoid placing SAP customers at unnecessary risk through premature disclosure or
insufficient information to protect their systems.