BugTraq
Re: SAP Security Contact Jan 05 2007 10:39PM
Thor (Hammer of God) (thor hammerofgod com) (2 replies)

You guys might want to put that on your web site. Probably somewhere under
"Contact Us" so that it is easy to, um, contact you specifically for
security issues.

Had it been someone other than Mark Litchfield or NGSSoftware who found the
unauthenticated remote vulnerability allowing for arbitrary code execution
in the SYSTEM context, they may very well have become frustrated with the
lack of contact info and the "you must mail this to the office" bit and seen
fit to just publish vulnerability details.

Something like security (at) sap (dot) com [email concealed] may seem obvious, but it's better if you
list specific contact info so it can be easily found.

t

On 1/5/07 6:41 AM, "Fritz.Bauspiess (at) sap (dot) com [email concealed]" <Fritz.Bauspiess (at) sap (dot) com [email concealed]>
spoketh to all:

> The contact email address is <security sap com>. Security issues will then be
> handled by our Security Response Team in direct communication with the
> reporter of the issues.
>
> Kind regards,
> Fritz Bauspiess, SAP NetWeaver Product Management Security
>
>

[ reply ]
Re: SAP Security Contact Jan 07 2007 12:14AM
Nicob (nicob nicob net) (2 replies)
Re: SAP Security Contact Jan 09 2007 02:09PM
Nick Boyce (nick boyce gmail com) (1 replies)
Re: SAP Security Contact Jan 10 2007 11:56PM
Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] (sbradcpa pacbell net)
Re: SAP Security Contact Jan 09 2007 06:02AM
Stan Bubrouski (stan bubrouski gmail com)
Re: SAP Security Contact Jan 06 2007 05:00PM
Ansgar -59cobalt- Wiechers (bugtraq planetcobalt net)


 

Privacy Statement
Copyright 2010, SecurityFocus