SAP Knowledge Base Article - Public

2271705 - What is the frequency and turnaround time of applying security patches if there is a newly discovered vulnerabilitity for SF?

Symptom

  • What is the frequency and turnaround time of applying security patches if there is a newly discovered vulnerability for SF?

Resolution

  • SuccessFactors Cloud Operations will review all high priority patches within three business days. The SuccessFactors Cloud Operations will categorize the importance of the patch according to the following:

  1. Emergency - an imminent threat to the SuccessFactors Network
  2. Critical - targets a security vulnerability
  3. Non Critical - a standard patch release update
  4. Not applicable to a Sucessfactors Network

 

  • SuccessFactors Cloud Operations' management must approve the patch and deployment schedule prior to implementation, to ensure maximum coordination and minimal disruption. Each patch release entails the creation and approval of a change request:
  1. Emergency patches will be deployed within 24 hours of assessment.
  2. Critical patches will be deployed during the first available maintenance window following successful testing.
  3. Not Critical patches will be deployed during a regularly scheduled maintenance window, generally within 90 days of assessment.
  • If application of a patch is expected to result in down time, all affected customers will be notified. 

Keywords

KBA , LOD-SF-PLT , Foundational Capabilities & Tools , How To

Product

SAP SuccessFactors HCM Core all versions