
Brazilian consumer goods giant Ypê runs SAP ERP without official vendor support, exposing supply chain to critical vulnerabilities
Ypê operates its SAP infrastructure through third-party provider Rimini Street, cutting ties with official German vendor patches. The decision exposes the company's core ERP—processing orders, logistics and financial data for a $600M revenue business—to documented security gaps that left critical SAP CVEs unpatched for 60-90 days in 2025. SAP attacks in Brazil rose 34% last year, targeting consumer goods firms with broad integration surfaces.

















