Skip to content

SAP Security Patch Day May 2023 – The latest SAP security updates

Welcome to another review of the monthly SAP Security Patch Day, published on 9 May 2023. We want to share the key information from these sources with you and show how our activities support the security of our clients' SAP systems. SAP, in its...

Welcome to another review of the monthly SAP Security Patch Day, published on 9 May 2023. We want to share the key information from these sources with you and show how our activities support the security of our clients’ SAP systems.

In its latest security bulletin, SAP released a number of patches aimed at fixing various security vulnerabilities. These included fixes for both on-premise and cloud products. This month, the most significant vulnerabilities were related to components such as SAP NetWeaver AS Java, SAP Business Client and SAP Commerce. Without the appropriate update, these vulnerabilities could lead to serious consequences, such as data integrity breaches, unauthorised access, or even complete takeover of the system.

Thanks to information provided by SecurityBridge, we gained an even deeper understanding of these issues. The platform provided detailed analyses of the impact and risk associated with each threat. It is important to remember that security patches should be deployed as soon as possible to minimise potential risk.

At SNOK, we are aware of how crucial it is to keep SAP systems up to date. That is why we offer a comprehensive service that includes both the deployment of the latest SAP patches and regular security audits. In addition, we use SecurityBridge software to monitor our clients’ systems in real time, enabling us to detect and respond to potential threats proactively.

We are always ready to work with our clients to help them keep their SAP systems in the best possible condition. The security of data and systems is our top priority, and the latest SAP patches are another step towards securing your organisation.

We encourage you to update your systems regularly and use the services of professional firms, such as SNOK, to ensure complete security. If you have any questions regarding the latest SAP patches or our services, please do not hesitate to contact us.

Remember that security is a process, not a destination. It requires constant attention, updates and reviews. With our expertise and the support of SecurityBridge, we are able not only to patch vulnerabilities, but also to monitor systems for newly emerging threats, so that we can respond and minimise risk as quickly as possible.

Finally, I would like to emphasise the importance of continuous training and skills development for teams managing SAP systems. The world of cybersecurity is dynamic and constantly evolving, and the only way to keep pace with these changes is through continuous education and adaptation.

If you have any questions about SAP Security Patch Day, our services, or would like to learn more about how we can help your organisation maintain the security of its SAP systems, please get in touch. We are here to help.

In summary, several significant vulnerabilities requiring immediate attention were identified during the May SAP Security Patch Day. Below is a table containing detailed information on each of them:

Found this useful? Please pass it on:

More from this series

Other

Secure SAP S/4HANA conversion - what the programme does to your attack surface

No steering committee ever minutes the decision to widen the attack surface for two years. That is exactly what gets approved: a change freeze on SAP ECC, production copies in project systems, emergency access for the system integrator, custom code that nobody scanned for security, and a RISE model where you raise the patch request. None of those steps is a mistake. Together they are a window.

Weekly Review W37: the core does not decide, what surrounds it does

Fifteen items from the window of 11 August - 10 September 2026: SAP Security Patch Day with a 10.0 note in the kernel, the network barrier in front of SAP removed, an official MCP server for BTP administration, a benchmark of eight SAP security pillars, a hidden payload in an email summary, OWASP Agentic Skills Top 10, a near-autonomous agentic attack on Taiwan, the harness as the deciding layer, UiPath results, Cartographer, Daniel Dines's book, the ISO 42001 annex trap, a model at critical level in cyber, AI server price rises and Mistral's funding round.

Your AI assistant refuses. That does not mean it is protecting you

The same request goes through once and is turned down the next time, depending on what happened earlier in the conversation. Three measurements show a refusal boundary that moves by tens of percentage points with no configuration change at all - which makes it unfit for the job our documents give it.

Get in touch