Re: SAP Security Contact




You guys might want to put that on your web site. Probably somewhere under
"Contact Us" so that it is easy to, um, contact you specifically for
security issues.

Had it been someone other than Mark Litchfield or NGSSoftware who found the
unauthenticated remote vulnerability allowing for arbitrary code execution
in the SYSTEM context, they may very well have become frustrated with the
lack of contact info and the "you must mail this to the office" bit and seen
fit to just publish vulnerability details.

Something like security@xxxxxxx may seem obvious, but it's better if you
list specific contact info so it can be easily found.

t




On 1/5/07 6:41 AM, "Fritz.Bauspiess@xxxxxxx" <Fritz.Bauspiess@xxxxxxx>
spoketh to all:

The contact email address is <security sap com>. Security issues will then be
handled by our Security Response Team in direct communication with the
reporter of the issues.

Kind regards,
Fritz Bauspiess, SAP NetWeaver Product Management Security





Relevant Pages

  • [NT] Vulnerability in HTML Help Allows Code Execution (MS05-001)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... * Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service ...
    (Securiteam)
  • [NT] Microsoft JScript Remote Code Execution (MS06-023)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... There is a remote code execution vulnerability in JScript. ... Configure Internet Explorer to prompt before running Active Scripting ...
    (Securiteam)
  • [NT] Vulnerability in Microsoft XML Core Services Could Allow Remote Code Execution (MS07-042)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... Vulnerability in Microsoft XML Core Services Could Allow Remote Code ... mode sets the security level for the Internet zone to High. ...
    (Securiteam)
  • [NT] Cumulative Security Update for Internet Explorer (MS05-052)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... A remote code execution vulnerability exists in the way Internet Explorer ...
    (Securiteam)
  • [NT] Microsoft Data Access Components (MDAC) Function Code Execution (MS06-014)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Get your security news from a reliable source. ... Microsoft Data Access Components Function Code Execution ... for the Internet security zone to prompt before running ActiveX controls. ...
    (Securiteam)