More than 95 percent of SAP systems exposed to vulnerabilities that could lead to a full compromise of business data, a security firm claims. The average time-to-patch for SAP vulnerabilities is more than 18 months — 12 months for SAP to issue fixes and 6 months for companies to deploy them. The most likely attack scenarios for compromising SAP systems are these: Pivoting from a lower-security system to a critical one to execute remote function modules; creating backdoor accounts on the SAP J2EE User Management Engine by exploiting vulnerabilities to gain access to SAP portals.”]

