Technology Blog Posts by SAP
cancel
Showing results for 
Search instead for 
Did you mean: 
Fabian_Richter
Associate
Associate
1,547

Earlier this month, we released the application vulnerability report (beta) for SAP Business Technology Platform (SAP BTP). You can use this new service to detect and remediate open-source application vulnerabilities in your SAP BTP deployed applications. 

What is this new service all about? 

Frequent security issues in open-source components endanger business data in customer deployed applications. Customers are responsible for performing vigilant patch and vulnerability management. By leveraging the new application vulnerability report for SAP BTP, open-source vulnerabilities in your Cloud Foundry applications can be detected and remediated. It's crucial to fix such vulnerabilities quickly, as attackers are usually aware of them and might try to break into vulnerable systems. 

What does the new application vulnerability report service offer you? 

The application vulnerability report supports you in the detection of vulnerabilities in custom applications during runtime. It enables you to act on criticality and other provided vulnerability details, like mitigation recommendations.  

If we take a closer look at the process, the service scans the applications using a proprietary scanning layer that utilizes open-source scanners as well as custom SAP BTP-specific and 0-day exploit targeted scanners. This unique combination offers a very broad and up-to-date coverage of vulnerabilities in your applications. By using an API, you can also integrate the report data into your incident and security workflow. 

Let’s have a quick look at the architecture overview: 

Fabian_Richter_0-1764845089098.png

Application Vulnerability Report for SAP BTP – Architecture Overview 

Get started now! 

You can find lots of useful information in this practical hands-on blog post: 

Introducing Application Vulnerability Report for Cloud Foundry Applications – Try It Now! 

The complete documentation is available on SAP Help Portal. 

Please note that this is a beta service available on SAP BTP for subaccounts in trial and enterprise accounts. It is currently available in the “cf-eu10” landscape. Once the beta phase is completed, we plan to roll out the service to other regions. 

If you are interested in what’s more to come, check out the road map in SAP Road Map Explorer. 

Try it out, and we look forward to your feedback! 

 

Also make sure to join our community to learn more about the security services and features in SAP Business Technology Platform here: 

https://community.sap.com/topics/btp-security