Re: SAP Security Contact
You guys might want to put that on your web site. Probably somewhere under
"Contact Us" so that it is easy to, um, contact you specifically for
security issues.
Had it been someone other than Mark Litchfield or NGSSoftware who found the
unauthenticated remote vulnerability allowing for arbitrary code execution
in the SYSTEM context, they may very well have become frustrated with the
lack of contact info and the "you must mail this to the office" bit and seen
fit to just publish vulnerability details.
Something like security@xxxxxxx may seem obvious, but it's better if you
list specific contact info so it can be easily found.
t
On 1/5/07 6:41 AM, "Fritz.Bauspiess@xxxxxxx" <Fritz.Bauspiess@xxxxxxx>
spoketh to all:
> The contact email address is <security sap com>. Security issues will then be
> handled by our Security Response Team in direct communication with the
> reporter of the issues.
>
> Kind regards,
> Fritz Bauspiess, SAP NetWeaver Product Management Security
>
>