Security company to release testing tool for SAP mobile access

Boston-based Onapsis will release a tool next month that tests if SAP systems have been correctly configured for mobile device use

As SAP invests heavily in mobile, a security testing company will release a tool next month to ensure mobile-accessible SAP systems are not vulnerable to hackers.

Boston-based Onapsis will release a new module for its X1 security suite, a product that performs automated security assessments, penetration testing and compliance audits for SAP's ERP (enterprise resource planning) software, said Mariano Nunez, Onapsis' CEO.

The module will focus in part on the SAP Mobile Platform, formerly known as the Sybase Unwired Platform Developer Center, which helps developers build SAP mobile applications for different devices and platforms. It also looks at the NetWeaver Gateway, an SAP server that links devices to back-end systems, Nunez said.

Exposing those back-end systems is complicated, and companies can face a risk of hacking if the systems are misconfigured or do not have up-to-date patches.

"We see that companies may not be paying enough attention to that and forgetting the devices," Nunez said. "Our empirical experience shows those systems are usually left insecure because of people not applying the latest patches or not following SAP's best security practices."

SAP is focused on mobile access, device management and security as more companies embrace bring-your-own-device policies. SAP supports iPhone, Android and Blackberry devices.

Sanjay Poonen, head of SAP's mobile division, said at the Sapphire Now conference in May that the company has more than 1,000 people working on mobile-related projects in areas such as retail, banking and consumer package goods.

Last year, SAP reported more than €222 million (US$293 million) in license revenue from its mobile-related business, a revenue stream that didn't exist two and half years prior, Poonen said.

"We think this market is really poised for an even bigger opportunity if you go even beyond devices," Poonen said. "This world is going to require us to think of mobile security in a whole new way."

Nunez said companies faces risks if, for example, a CRM (customer relationship management) system is incorrectly configured for access by mobile devices, opening a door for hackers using attack tools for Web services.

X1's mobile security module looks at what functions and processes are exposed in the back-end systems and not on the mobile application itself, Nunez said. It alerts users to security vulnerabilities and tells users how to fix the issues. The module is scheduled to be released next month, and will be free to X1 subscribers.

Onapsis is also scheduled to present two SAP security workshops at the Black Hat security conference in Las Vegas, which kicks off on July 27. The workshops, which are not product focused, will look at SAP security from an academic perspective, Nunez said.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags securityfraudmobilemobile applicationsdata breachintrusionOnapsis

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Cool Tech

Breitling Superocean Heritage Chronographe 44

Learn more >

SanDisk MicroSDXC™ for Nintendo® Switch™

Learn more >

Toys for Boys

Family Friendly

Panasonic 4K UHD Blu-Ray Player and Full HD Recorder with Netflix - UBT1GL-K

Learn more >

Stocking Stuffer

Razer DeathAdder Expert Ergonomic Gaming Mouse

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?