SAP Afaria

Last updated

SAP Afaria is a mobile device management software product. It helps large organizations connect mobile devices such as smartphones and tablet computers to the company network, and to simplify the information technology (IT) tasks associated with buying, deploying, securing and maintaining such devices.

Contents

History

XcelleNet originally developed the product that would eventually become Afaria, [1] releasing the first version, called SessionXpress, in 1997. It was the first product of the company’s Net-Essentials product suite, and allowed system administrators to remotely manage client systems, including disks, files and sessions. [2] XcelleNet renamed the product to RemoteWare Express later that same year (1997), to CONNECT:Manage in 1999, and finally to Afaria in 2000.

Sterling Commerce acquired XcelleNet in 1998, renaming the software CONNECT:Manage (and the group Sterling Commerce Managed Systems Division), but then divested itself a year later. XcelleNet, Inc. became an independent, privately held company in February 2000, [3] and released version 3.5 of the product in May 2000, as Afaria for Handhelds, and version 4.0 in June 2000 as Afaria.

Network Computing magazine awarded its Editors Choice award to Afaria version 3.4 in July 2000, [4] and version 4.51 in February 2002. [5]

Sybase acquired XcelleNet in 2004. [1] In 2012, Sybase Afaria became SAP Afaria, following the acquisition of Sybase by SAP. [6]

Market intelligence firm International Data Corporation (IDC) first recognized Afaria as the leader in mobile device management in June 2001, and has continued to do so every year since, through 2011. In 2011, Gartner identified Afaria as one of the top mobile device management platforms in the first Gartner Magic Quadrant report on the mobile device management market. [7] In the Gartner Quadrant for MDM of June 2014 SAP Afaria is in the Challengers Quadrant.

Design features

SAP Afaria uses a session-based approach when it communicates with mobile devices in the field. [8] This allows it to circumvent issues related to intermittent connections caused by roaming devices that might lose their network connectivity during a data transmission in progress.

SAP Afaria organizes its tasks into worklists and sendlists. These are called channels. When a device, or "client," connects to the server (called a transmitter), the channels execute their tasks. Administrators manipulate the tasks in the channels using a graphical interface with a tree structure.

To download the device component of the software (called provisioning), an organization’s IT department sends an SMS or SMTP email to each device with a link to the Afaria server. End users (or IT) can click the link to start the download. Or users download the client from an online distribution platform and enter a short code that enrolls the device and applies policies. [9]

Usage

Companies commonly use SAP Afaria to manage a large number of company-owned or employee-owned mobile devices that employees use for work. Due to the increasing popularity of smartphones and other mobile devices in the general population, many people now bring their own devices (BYOD) to work. Companies are finding that they must support the use of employees' personal mobile devices in conjunction with corporate email and other applications. [10] An organization that does so benefits from the increased engagement and productivity of its workforce, as employees are able to more easily respond to work tasks when they’re away from the office. [11]

Mobile network operators and service providers are two other types of companies that frequently employ mobile device management software such as SAP Afaria.

Security

Several security issues in SAP Afaria were identified. [12] While the total number of those vulnerabilities is relatively small, most of them critical and can be used to access the system.

According to security researcher Dmitry Chastukhin, one of the vulnerabilities allowed attackers to take control of all mobile devices connected to it with by mimic a command sent from the server to a mobile client. [13] [14] This command is sent in the form of an SMS message, signed by a SHA256 hash.

See also

Related Research Articles

<span class="mw-page-title-main">Sybase</span> Enterprise software and services company

Sybase, Inc. was an enterprise software and services company. The company produced software relating to relational databases, with facilities located in California and Massachusetts. Sybase was acquired by SAP in 2010; SAP ceased using the Sybase name in 2014.

Software AG is a German multinational software corporation that develops enterprise software for business process management, integration, and big data analytics. The company is headquartered in Darmstadt, Germany, and has offices worldwide.

HCL Sametime Premium is a client–server application and middleware platform that provides real-time, unified communications and collaboration for enterprises. Those capabilities include presence information, enterprise instant messaging, web conferencing, community collaboration, and telephony capabilities and integration. Currently it is developed and sold by HCL Software, a division of Indian company HCL Technologies, until 2019 by the Lotus Software division of IBM.

<span class="mw-page-title-main">Windows Mobile</span> Discontinued family of mobile operating systems by Microsoft

Windows Mobile was a family of mobile operating systems developed by Microsoft for smartphones and personal digital assistants.

SAP NetWeaver is a software stack for many of SAP SE's applications. The SAP NetWeaver Application Server, sometimes referred to as WebAS, is the runtime environment for the SAP applications and all of the mySAP Business Suite runs on SAP WebAS: supplier relationship management (SRM), customer relationship management (CRM), supply chain management (SCM), product lifecycle management (PLM), enterprise resource planning (ERP), transportation management system (TMS).

SAP NetWeaver Master Data Management (SAP NW MDM) is a component of SAP's NetWeaver product group and is used as a platform to consolidate, cleanse and synchronise a single version of the truth for master data within a heterogeneous application landscape. It has the ability to distribute internally and externally to SAP and non-SAP applications. SAP MDM is a key enabler of SAP Service-Oriented Architecture. Standard system architecture would consist of a single central MDM server connected to client systems through SAP Exchange Infrastructure using XML documents, although connectivity without SAP XI can also be achieved. There are five standard implementation scenarios:

  1. Content Consolidation - centralised cleansing, de-duplication and consolidation, enabling key mapping and consolidated group reporting in SAP BI. No re-distribution of cleansed data.
  2. Master Data Harmonisation - as for Content Consolidation, plus re-distribution of cleansed, consolidated master data.
  3. Central Master data management - as for Master Data Harmonisation, but all master data is maintained in the central MDM system. No maintenance of master data occurs in the connected client systems.
  4. Rich Product Content Management - Catalogue management and publishing. Uses elements of Content Consolidation to centrally store rich content (images, PDF files, video, sound etc.) together with standard content in order to produce product catalogues (web or print). Has standard adapters to export content to Desktop Publishing packages.
  5. Global Data Synchronization - provides consistent trade item information exchange with retailers through data hubs (e.g. 1SYNC)
<span class="mw-page-title-main">Sybase iAnywhere</span>

Sybase iAnywhere, is a subsidiary of Sybase specializing in mobile computing, management and security and enterprise database software. SQL Anywhere, formerly known as SQL Anywhere Studio or Adaptive Server Anywhere (ASA), is the company's flagship relational database management system (RDBMS). SQL Anywhere powers popular applications such as Intuit, Inc.'s QuickBooks, and the devices of 140,000 census workers during the 2010 United States Census. The product's customers include Brinks, Kodak, Pepsi Bottling Group (PBG), MICROS Systems, Inc. and the United States Navy. In August 2008.

SAP SQL Anywhere is a proprietary relational database management system (RDBMS) product from SAP. SQL Anywhere was known as Sybase SQL Anywhere prior to the acquisition of Sybase by SAP.

Mobile device management (MDM) is the administration of mobile devices, such as smartphones, tablet computers, and laptops. MDM is usually implemented with the use of a third-party product that has management features for particular vendors of mobile devices. Though closely related to Enterprise Mobility Management and Unified Endpoint Management, MDM differs slightly from both: unlike MDM, EMM includes mobile information management, BYOD, mobile application management and mobile content management, whereas UEM provides device management for endpoints like desktops, printers, IoT devices, and wearables as well.

<span class="mw-page-title-main">Symantec Endpoint Protection</span> Computer security software

Symantec Endpoint Protection, developed by Broadcom Inc., is a security software suite that consists of anti-malware, intrusion prevention and firewall features for server and desktop computers. It has the largest market-share of any product for endpoint security.

Syclo, LLC was a mobile enterprise application platform (MEAP) and software provider based in the Chicago suburb of Hoffman Estates, Illinois, offering mobile applications to extend enterprise systems, including packaged software for Enterprise Resource Planning (ERP), Enterprise Asset Management (EAM), and Customer Relationship Management (CRM), to handhelds, smartphones, and mobile computers for technicians and staff performing work away from a central office.

A mobile enterprise application platform (MEAP) is a suite of products and services that enable the development of mobile applications. The term was coined in a Gartner Magic Quadrant report in 2008 when they renamed their "multichannel access gateway mar" e t".

Intrexx is a cross-platform integrated development environment for the creation and operation of multilingual web-based applications, intranets, social intranets, enterprise portals and customer portals (extranets) as well as Industry 4.0 solutions as of 2018. A portal is created based on the drag and drop principle. Intrexx is a low-code development platform. Most applications can be created via drag & drop but manual coding can be added where necessary.

SAP Mobile Platform is a mobile enterprise application platform designed to simplify the task of creating applications that connect business data to mobile devices for workflow management and back-office integration. SAP Mobile Platform provides a layer of middleware between heterogeneous back-end data sources, such as relational databases, enterprise applications and files, and the mobile devices that need to read and write back-end data.

Zenprise provides Mobile Device Management (MDM) solutions to enterprises. The company's solutions are available in both on-premise and cloud-based (SaaS) versions. Zenprise MobileManager and Zencloud allow companies and government agencies to manage and secure mobile devices, including iOS, Android, BlackBerry, Windows Mobile, and Symbian.

<span class="mw-page-title-main">Arcplan</span> Business intelligence software company

Arcplan is a software for business intelligence (BI), budgeting, planning & forecasting (BP&F), business analytics and collaborative Business Intelligence. It is the enhancement of the enterprise software inSight® and dynaSight of the former German provider arcplan Information Services GmbH.

Absolute Software Corporation is an American–Canadian company that provides products and services in the fields of endpoint security and zero trust security. The company is headquartered in Vancouver, British Columbia, Canada. Regional offices include: Victoria, British Columbia, Canada; Austin, Texas; Ankeny, Iowa; Boulder, Colorado; San Jose, California; and Seattle, Washington in the U.S.; and in Reading, UK; and Ho Chi Minh City, Vietnam. Absolute is a publicly traded company on the Toronto Stock Exchange (TSX) and Nasdaq.

MobileIron Inc. was an American software company that provided unified endpoint and enterprise mobility management (EMM) for mobile devices, such as multi-factor authentication (MFA). The company announced in September 2020 it was being acquired by Ivanti.

Unified endpoint management (UEM) is a class of software tools that provide a single management interface for mobile, PC and other devices. It is an evolution of, and replacement for, mobile device management (MDM) and enterprise mobility management (EMM) and client management tools.

References

  1. 1 2 Morrison, Todd (March 29, 2011), Sybase Afaria Mobile Device Management Finally Needed, Analysts Say, TechTarget
  2. Balderston, Jim (February 17, 1997), Vendors Offer Smart Data Delivery Systems, InfoWorld
  3. Greene, Tim (March 27, 2000), Handheld Device Mgmt. Help on Tap From Xcellenet, Computerworld
  4. Hoffman, Richard (July 24, 2000), Living in Nomad's Land: Managing Mobile Devices, Network Computing
  5. Robinson, Cornell W. (February 4, 2002), Enable Your Mobile Apps, Network Computing
  6. Worthington, David (May 13, 2010), SAP to purchase Sybase in cash deal, Software Development Times
  7. Heary, James (April 30, 2011), Gartner Releases first MDM Magic Quadrant Report, NetworkWorld
  8. Berkeley, Travis (May 7, 2001), The Long Arm of the LAN, Network World
  9. Henderson, Tom (May 9, 2011), How Mobile Device Management Works, IT World
  10. Plummer, Daryl (November 2010), Top Predictions for IT Organizations and Users for 2011 and Beyond, Gartner, archived from the original on November 30, 2010
  11. Ryan, Sean (August 2009), The State of Mobile Enterprise Software in 2009: An IDC Survey
  12. "SAP Afaria : List of security vulnerabilities". www.cvedetails.com. Retrieved 2017-03-09.
  13. Zetter, Kim. "Hack Brief: Mobile Manager's Security Hole Would Let Hackers Wipe Phones". WIRED. Retrieved 2017-03-09.
  14. "SAP Afaria: how to wipe mobile devices clean with one text message". ERPScan. Retrieved 2017-03-30.