Skip to content

Contents

Keep the Whole SAP Business One Environment Up to Date

Your ERP supports the everyday running of your business. Keeping it secure means maintaining every layer it depends on.

Whether SAP Business One runs on premises, in a data centre or in a hosted cloud environment, it should be maintained as a supported, regularly updated business platform. That includes the application, database, operating systems, security software and the services connecting it to other systems.

Your environment holds financial information, customer and supplier records, inventory and the transactions that keep your business operating. A security incident can interrupt order processing, dispatch, purchasing and reporting, or allow information to be accessed or changed without authorisation.

A system can continue working normally while still containing a known security vulnerability.

For customers, the practical priority is to establish what is installed, confirm that it remains supported and agree who keeps each component up to date. Security maintenance needs to be part of the ongoing support plan.

Security Covers the Complete Environment

A review should cover the full SAP Business One landscape, including the devices people use to access it and the connections that exchange data with other applications.

Six areas to keep supported, maintained and reviewed

01

Infrastructure and Access

Operating systems, virtualisation, firewalls, remote access, workstations and remote desktop hosts.

02

Database Platforms

Microsoft SQL Server or SAP HANA, including security updates and supported combinations of software versions.

03

SAP Business One

Application and client builds, Server Tools, System Landscape Directory (SLD), authentication services and other installed components.

04

Integrations and Add-ons

B1if, Service Layer, connectors, add-ons, custom integration code and the software they depend on.

05

Endpoint Protection

Supported security agents and engines, current malware intelligence, alert monitoring and reviewed exclusions.

06

Backups and Recovery

Protected backups of databases, configuration and integration logic, supported by practical restoration testing.

Antivirus and Security Patches Have Different Jobs

Antivirus and endpoint detection and response help detect and contain malicious activity. Security patches repair weaknesses in software. Both need ongoing attention.

Updating malware definitions does not install SAP application fixes. Windows updates do not automatically update B1if or Service Layer. A current security agent also does not establish that the operating system or database underneath it remains supported.

Australian Signals Directorate guidance treats application patching and operating system patching as core security measures. These controls work alongside access restrictions, monitoring and recovery arrangements. [1] [9]

Hosting Does Not Remove the Need for Application Maintenance

A hosting agreement may cover infrastructure without covering SAP upgrades, add-ons or integration code. The customer, IT provider, hosting provider and SAP partner should explicitly agree who maintains each layer and who responds to security alerts.

The useful question is: who is responsible for each component, and how do we confirm that the required updates have been applied?

Why SAP Application Updates Matter

SAP publishes security corrections for Business One components alongside functional improvements. Its public security bulletins include the following examples, showing why the application and its supporting services belong in the patching programme. [3] [4]

Examples published in SAP security bulletins
Component Published security issue SAP reference
Service Layer March 2025
Authentication weakness
Note 3561045
CVE-2025-26658
Integration Framework (B1if) June 2025
Security configuration weakness
Note 3594258
CVE-2025-42998
System Landscape Directory (SLD) August 2025
Authorisation weakness
Note 3625403
CVE-2025-42951
Business One Client February 2026
Information disclosure involving memory dump files
Note 3679346
CVE-2026-24319

These are examples of published issues, not a finding that a particular customer is vulnerable. Check applicability, affected builds, corrective versions and required configuration changes against the current SAP Security Note. Detailed notes may require an SAP support login.

Support Must Cover the Complete Platform

A supported deployment uses compatible software versions that remain within the relevant vendors’ support arrangements, together with applicable security fixes. Check SAP’s Platform Support Matrix alongside its current availability information, administration guides and the compatibility requirements of your add-on suppliers. [2] [10]

SAP’s matrix dated 28 August 2026 identifies SAP Business One 10.0 as in maintenance and versions 9.0 through 9.3 as out of maintenance. However, the description “version 10” alone does not establish whether an installation contains the required security corrections. The exact feature package, support package, patch or hotfix level matters. [2] [3]

A maintenance entitlement makes updates available. It does not demonstrate that those updates have been installed.

Security Updates Still Matter When You Do Not Need New Features

Your business may have no immediate need for new functionality and still require an update for security or platform compatibility. Plan a tested release baseline and a regular maintenance window, with a faster route for urgent corrections.

Where an add-on prevents an essential update, agree a resolution with its supplier and time-limited protective measures while the dependency is addressed. Keep the update on an agreed completion plan. [1]

The Security Case for Reviewing B1if Integrations

Integrations extend the value of SAP Business One across eCommerce, warehousing, reporting and other business applications. They also introduce services, accounts and software dependencies that need ongoing maintenance.

B1if and Service Layer serve different roles. B1if is an integration framework; Service Layer provides APIs for accessing SAP Business One data and services. B1if can itself use Service Layer, so using the API does not necessarily mean that B1if has been removed. [5] [6]

At Cloud Factory, we recommend assessing whether Service Layer can support a simpler, more controlled integration design. The benefits below are opportunities to evaluate against the existing solution; they are not a blanket SAP claim that one component is always more secure.

Where Service Layer can strengthen an integration design
Potential benefit When the benefit is achieved
Fewer Components to Maintain A suitable integration can retire an otherwise unnecessary B1if installation and its associated runtime or proxy components. Keeping both stacks running does not deliver this reduction.
Less Direct Database Access External applications use the supported API for the operations they need, instead of holding database credentials or connecting directly to SQL Server or SAP HANA.
More Controlled Integration Identities Dedicated identities receive only the permissions they need. SAP documents IAM token flows for Service Layer, including a daemon service using a technical user. Availability depends on the target version and setup. [7]
A Managed API Boundary HTTPS endpoints can sit behind appropriately configured network and API controls, with restricted access and monitoring. SAP documents TLS 1.2 and 1.3 for Service Layer; verify the target release and configuration. [8]

Encrypted connections, restricted permissions and good credential management are not exclusive to Service Layer. The strongest migration case is a demonstrable reduction in exposed services, excessive access or maintenance complexity in your actual environment.

Migration Needs a Functional and Security Assessment

Service Layer is not a drop-in replacement for every B1if scenario. Check API coverage, event handling, scheduling, transformations, retries, monitoring and dependent SAP or third-party solutions. Any replacement middleware or custom integration also needs an owner and ongoing maintenance.

Service Layer still needs security updates. SAP’s March 2025 authentication correction is direct evidence of this. Restrict access to its endpoints, avoid shared superuser accounts and validate authentication and authorisation for each connection. Enabling MFA for human users does not automatically protect unattended integrations. [3] [7]

Once a replacement is proven, retire unused endpoints, accounts, credentials and services. Where B1if remains necessary, keep it supported, patched, restricted and monitored. A migration project should not delay an urgent correction to the existing environment.

A Practical Maintenance Standard for Customers

Cloud Factory recommends making the following responsibilities explicit within every SAP Business One support and hosting arrangement. The implementation should reflect your environment, exposure and business needs.

1. Maintain a Complete Version and Ownership Record

Record the exact SAP build, database and operating system versions, installed services, add-ons and integration runtimes. Include workstations, remote desktop hosts and test systems. Name the party responsible for updates, alert review and escalation for each component.

2. Review Advisories and Act According to Risk

Review SAP Security Notes and relevant vendor advisories regularly, with alerts for urgent issues between scheduled reviews. Prioritise by severity, exposure and evidence of exploitation. ASD’s Essential Eight includes accelerated treatment of critical or exploited vulnerabilities in online services; an annual upgrade alone is not an adequate response process. [1] [9]

3. Use Supported Update and Testing Procedures

Confirm compatibility with SAP, the database vendor and add-on suppliers. Use SAP-supported procedures for bundled components such as Java, Tomcat and web servers; check supportability before independently replacing dependencies. Test key transactions, reports, integrations and authentication, with a backup and rollback plan.

4. Secure Access as Well as Software Versions

Apply least privilege, remove unused accounts and protect administrative and remote access with MFA where supported. Keep database and administration interfaces private. Use valid, trusted certificates and monitor expiry. Restrict integration endpoints to their intended callers and protect stored credentials and tokens. Configure and verify security features after an upgrade.

5. Keep Protection Active and Prove Recovery

Maintain supported antivirus or endpoint protection, including agent and engine updates as well as malware intelligence. Monitor alerts and review exclusions. Protect backups of databases and the configuration, integration logic and recovery material needed to rebuild the environment. Test restoration against agreed business recovery requirements.

6. Document Exceptions and Their End Dates

When a required update must be deferred, record the reason, risk owner, temporary controls and target completion date. Review those controls regularly and keep the work needed to restore a supported environment on the agreed schedule.

Can Your Business Answer These Questions?

  • What exact SAP, database, operating system and integration versions are we running?
  • Who confirms support status and reviews relevant security advisories?
  • When were the required updates last applied and verified?
  • How do we handle an urgent security correction between planned upgrades?
  • When did we last demonstrate that we could restore the environment?

Keep Your SAP Business One Environment Ready for the Future

Keeping SAP Business One current protects the platform your business relies on and provides a supported foundation for future improvements. Security maintenance and plans for new functionality should be coordinated, with clear priorities and ownership.

Cloud Factory recommends a coordinated review of your SAP Business One application, hosting platform and integrations. The outcome should be a clear support baseline, an agreed update schedule, a route for urgent security fixes and a prioritised plan for older integration components.

Where Service Layer can simplify the design and improve access control, assess the migration alongside the business processes it must support. We can work with your team, IT provider and hosting provider to identify the next steps.

Arrange a Review with Cloud Factory

Discuss your current environment, maintenance responsibilities and priorities for keeping SAP Business One secure and supported.

Talk to Cloud Factory

Sources and Further Reading

This article draws on SAP and Australian Signals Directorate guidance. Support status and remediation details can change, so check the current vendor material when planning work. The examples are not an assessment of an individual installation or a claim of Essential Eight maturity.

  1. Australian Signals Directorate — Patching applications and operating systems
  2. SAP — SAP Business One Platform Support Matrix
    Version 1.39, dated 28 August 2026. Read alongside current availability information and administration guides.
  3. SAP — Security Patch Day Bulletins 2025
    March: Note 3561045. June: Note 3594258. August: Note 3625403.
  4. SAP — Security Patch Day February 2026
    Note 3679346 on Business One client memory dump files.
  5. SAP — Working with SAP Business One Service Layer
  6. SAP — Integration Framework Company SLD Configuration
    Used for the architectural distinction between connection types, not as a current support matrix.
  7. SAP — Identity and Authentication Management Walkthrough for Daemon Service
    Technical-user token flow; check availability for the target version and configuration.
  8. SAP — Administrator Guide Service Layer communication security
  9. Australian Signals Directorate — Essential Eight maturity model
  10. SAP — SAP Business One version for SAP HANA Platform Support Matrix
    Use the corresponding platform matrix for SAP HANA deployments.