Security company to release testing tool for SAP mobile access

Boston-based Onapsis will release a tool next month that tests if SAP systems have been correctly configured for mobile device use

As SAP invests heavily in mobile, a security testing company will release a tool next month to ensure mobile-accessible SAP systems are not vulnerable to hackers.

Boston-based Onapsis will release a new module for its X1 security suite, a product that performs automated security assessments, penetration testing and compliance audits for SAP's ERP (enterprise resource planning) software, said Mariano Nunez, Onapsis' CEO.

The module will focus in part on the SAP Mobile Platform, formerly known as the Sybase Unwired Platform Developer Center, which helps developers build SAP mobile applications for different devices and platforms. It also looks at the NetWeaver Gateway, an SAP server that links devices to back-end systems, Nunez said.

Exposing those back-end systems is complicated, and companies can face a risk of hacking if the systems are misconfigured or do not have up-to-date patches.

"We see that companies may not be paying enough attention to that and forgetting the devices," Nunez said. "Our empirical experience shows those systems are usually left insecure because of people not applying the latest patches or not following SAP's best security practices."

SAP is focused on mobile access, device management and security as more companies embrace bring-your-own-device policies. SAP supports iPhone, Android and Blackberry devices.

Sanjay Poonen, head of SAP's mobile division, said at the Sapphire Now conference in May that the company has more than 1,000 people working on mobile-related projects in areas such as retail, banking and consumer package goods.

Last year, SAP reported more than €222 million (US$293 million) in license revenue from its mobile-related business, a revenue stream that didn't exist two and half years prior, Poonen said.

"We think this market is really poised for an even bigger opportunity if you go even beyond devices," Poonen said. "This world is going to require us to think of mobile security in a whole new way."

Nunez said companies faces risks if, for example, a CRM (customer relationship management) system is incorrectly configured for access by mobile devices, opening a door for hackers using attack tools for Web services.

X1's mobile security module looks at what functions and processes are exposed in the back-end systems and not on the mobile application itself, Nunez said. It alerts users to security vulnerabilities and tells users how to fix the issues. The module is scheduled to be released next month, and will be free to X1 subscribers.

Onapsis is also scheduled to present two SAP security workshops at the Black Hat security conference in Las Vegas, which kicks off on July 27. The workshops, which are not product focused, will look at SAP security from an academic perspective, Nunez said.

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags mobile applicationsintrusionOnapsissecuritydata breachmobilefraud

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

David Coyle

Brother PocketJet PJ-773 A4 Portable Thermal Printer

I rate the printer as a 5 out of 5 stars as it has been able to fit seamlessly into my busy and mobile lifestyle.

Kurt Hegetschweiler

Brother PocketJet PJ-773 A4 Portable Thermal Printer

It’s perfect for mobile workers. Just take it out — it’s small enough to sit anywhere — turn it on, load a sheet of paper, and start printing.

Matthew Stivala

HP OfficeJet 250 Mobile Printer

The HP OfficeJet 250 Mobile Printer is a great device that fits perfectly into my fast paced and mobile lifestyle. My first impression of the printer itself was how incredibly compact and sleek the device was.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?