On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

March 22nd, 2007

Oracle sues SAP; alleges 'corporate theft on a grand scale'

Posted by Larry Dignan @ 11:39 am

Categories: General, Oracle, SAP

Tags:

In Focus » See more posts on: Oracle, SAP

The war between Oracle and SAP is about to move beyond enterprise applications to the courtroom.

Oracle said Wednesday that it has sued SAP "about corporate theft on a grand scale" seeking undisclosed damages. Oracle also argues that the theft formed the basis of SAP's "Safe Passage" program, which is designed to entice Oracle customers to switch to SAP. SAP won't comment until it has reviewed the complaint.

"We have just been notified of the lawsuit, and have taken note of the Oracle press release," said an SAP spokesman. "We are still reviewing the matter, and, until we have a chance to study the allegations, SAP will follow is standard policy of not commenting on pending litigation." 

According to the complaint, Oracle discovered in November "heavy download activity on Oracle's customer support Web site for PeopleSoft and J.D. Edwards products. The site contained information on program and software updates, patches and instructions. Oracle, however, alleges that software and technical support materials, which have limited download rights, were downloaded en masse from an IP address originating in Bryan, Texas, home of SAP's TomorrowNow (SAP TN) subsidiary, which offers support to PeopleSoft and J.D. Edwards customers.

"Oracle’s server logs have recorded access through this same IP address by computers labeled with SAP identifiers using SAP IP addresses," said Oracle, which noted that customers didn't partake in downloading. The lawsuit is just the latest volley in an ongoing war between SAP and Oracle.

The two parties increasingly take jabs at each other. And the fight has increasingly become one of collecting support and maintenance fees from technology buyers. Indeed, SAP bought TomorrowNow in 2005 partially as a way to convince Oracle customers to switch to SAP.

In the complaint Oracle said:

"Oracle brings this lawsuit after discovering that SAP is engaged in systematic, illegal access to – and taking from – Oracle’s computerized customer support systems. Through this scheme, SAP has stolen thousands of proprietary, copyrighted software products and other confidential materials that Oracle developed to service its own support customers. SAP gained repeated and unauthorized access, in many cases by use of pretextual customer log-in credentials, to Oracle’s proprietary, password-protected customer support website. From that website, SAP has copied and swept thousands of Oracle software products and other proprietary and confidential materials onto its own servers. As a result, SAP has compiled an illegal library of Oracle’s copyrighted software code and other materials. This storehouse of stolen Oracle intellectual property enables SAP to offer cut rate support services to customers who use Oracle software, and to attempt to lure them to SAP’s applications software platform and away from Oracle’s."

Oracle is seeking "to stop SAP’s illegal intrusions and theft, to prevent SAP from using the materials it has illegally acquired to compete with Oracle, and to recover damages and attorneys’ fees."

Oracle is alleging that SAP used the company's support documents to undercut pricing in an attempt to gain customers. Oracle claims it saw a spike in downloads in November and December of 2006 as SAP employees downloaded information.

From the complaint:

"SAP employees using the log-in credentials of Oracle customers with expired or soon-to-expire support rights had, in a matter of a few days or less, accessed and copied thousands of individual Software and Support Materials. For a significant number of these mass downloads, the users lacked any contractual right even to access, let alone copy, the Software and Support Materials. The downloads spanned every library in the Customer Connection support website. For example, using one customer’s credentials, SAP suddenly downloaded an average of over 1,800 items per day for four days straight (compared to that customer’s normal downloads averaging 20 per month). Other purported customers hit the Oracle site and harvested Software and Support Materials after they had cancelled all support with Oracle in favor of SAP TN. Moreover, these mass downloads captured Software and Support Materials that were clearly of no use to the “customers” in whose names they were taken. Indeed, the materials copied not only related to unlicensed products, but to entire Oracle product families that the customers had not licensed."

Apparently, the downloading continued into the new year. In January 2007, Oracle claims that SAP logged in as Honeywell International and accessed the company's support materials "in virtually every product library in every line of business."

Oracle continues:

"This copying went well beyond the products that Honeywell had licensed and to which it had authorized access. In other examples, users from SAP logged in using the credentials of recently departed customers, like Metro Machine Corp., and downloaded Software and Support Materials even after the customer had dropped its support rights with Oracle. Oracle has found many examples of similar activity. Across its entire library of Software and Support Materials in Customer Connection, Oracle to date has identified more than 10,000 unauthorized downloads of Software and Support Materials relating to hundreds of different software programs."

The techniques allegedly deployed by SAP's Tomorrow Now unit were also detailed.

"SAP employees used the log-in IDs of multiple customers, combined with phony user log-in information, to gain access to Oracle’s system under false pretexts. Employing these techniques, SAP users effectively swept much of the contents of Oracle’s system onto SAP’s servers. These “customer users” supplied user information (such as user name, email address, and phone number) that did not match the customer at all. In some cases, this user information did not match anything: it was fake. For example, some users logged in with the user names of “xx” “ss” “User” and “NULL.” Others used phony email addresses like “test@testyomama.com” and fake phone numbers such as “7777777777” and “123 456 7897.” In other cases, SAP blended log-in information from multiple customers with fake information. For example, one user name connected to an SAP IP address appears to have logged in using the credentials of seven different customers in a span of just 15 days – all from SAP computers in Bryan, Texas."

The common thread in these intrusions according to Oracle: All of the accounts accessed were about Oracle customers that became or were about to become SAP TomorrowNow customers.

"In the course of this investigation, Oracle discovered a pattern. Frequently, in the month before a customer’s Oracle support expired, a user purporting to be that customer, employing the customer’s log-in credentials, would access Oracle’s system and download large quantities of Software and Support Materials, including dozens, hundreds, or thousands of products beyond the scope of the specific customer’s licensed products and permitted access. Some of these apparent customer users even downloaded materials after their contractual support rights had expired."

"Oracle’s support servers have even received hits from URL addresses in the course of these unlawful downloads with SAP TN directly in the name (e.g. http://hqitpc01.tomorrownow.com). Indeed, for many of these downloads, Oracle noticed that SAP TN did not even bother to change the false user information from customer to customer when it logged in."

Oracle goes on to document the war between the database and applications giant and SAP for customers. The customer accounts allegedly accessed read like a who's who of corporate America.

Oracle has uncovered unlicensed downloads linked to SAP TN on behalf of numerous customers, including without limitation, Abbott Laboratories, Abitibi-Consolidated, Inc., Bear, Stearns & Co., Berri Limited, Border Foods, Caterpillar Elphinstone,Distribution & Auto Service, Fuelserv Limited, Grupo Costamex, Helzberg Diamonds, HerbertWaldman, Honeywell International, Interbrew UK, Laird Plastics, Merck & Co., Metro Machine Corp., Mortice Kern Systems, Inc., National Manufacturing, NGC Management Limited, OCE Technologies, B.V., Ronis, S.A., Smithfield Foods, SPX Corporation, Stora Enso, Texas Association of School Boards, VSM Group AB, and Yazaki North America.

If this lawsuit goes to trial, it will be interesting for another reason: Details about the cutthroat nature of the enterprise applications business, pricing practices, customer testimony and corporate espionage precedent are likely to emerge.

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

For daily updates, follow Larry on Twitter.

Email Larry Dignan

Subscribe to Between the Lines via Email alerts or RSS.

  • Talkback
  • Most Recent of 74 Talkback(s)
RE: Oracle sues SAP; alleges 'corporate theft on a grand scale'
MKV to XVID Converter||MKV to PS3 Converter both are brili tools for mkv convertible videos.... (Read the rest)
Posted by: ujhrdngjk Posted on: 08/12/09 You are currently: a Guest | | Terms of Use
Framed?  Yensi717 | 03/22/07
Not hardly...  No_Ax_to_Grind | 03/22/07
SAP isn't ever gonna pay a penny  shipsone@... | 03/22/07
Hmmmm  maldain | 03/22/07
Hmmm...  bportlock | 03/22/07
unfair competition  james.strange@... | 03/22/07
RMS Smiling all around  Too Old For IT | 03/23/07
WHAT  Aussie_Troll | 03/23/07
silly  georgef | 03/24/07
Larry Ellison is Megalomaniac? Offensive to Meglomaniacs!  Too Old For IT | 03/23/07
Oracle can't foresee the future?  archetuthus | 03/22/07
This is the same Oracle ...  Too Old For IT | 03/23/07
Who's in charge of security at Oracle?  cicuta | 03/22/07
Security defined.  Narg | 03/22/07
Not the same thing here  georgeou | 03/22/07
Not quite right, George  Zeppo9191 | 03/23/07
SAP encourced their customers to download docs legally  georgeou | 03/23/07
Theft's OK when it's easy?  blunderdog | 03/23/07
It's not the same as taking fruit  georgeou | 03/23/07
Red Herrings and EULAs  blunderdog | 03/23/07
Sort of but not really.  osreinstall | 03/23/07
security defined  adr5@... | 03/23/07
re: who's in charge of security  akautz2@... | 03/22/07
That's right...  guevaradavid@... | 03/23/07
My Oracle Rep Just Called ...  Too Old For IT | 03/23/07
Well done! 9.0  John L. Ries | 03/23/07
That's a good Mike Cox impression happy  georgeou | 03/23/07
I don't think it's a security issue  CaptainDave | 03/25/07
Send in the RIAA/MPAA - that'll learn 'em!!  Carrion | 03/22/07
Let me get this straight  John L. Ries | 03/22/07
Alex  Alexandre Jaquet | 03/22/07
Oracle sues SAP  bill@... | 03/22/07
no use your sense  sen_smiles01 | 03/22/07
Sense?  Fred Nurks | 03/22/07
There are laws against enticement and entrapment  georgeou | 03/22/07
... there are people named Mr Null...  CaptainDave | 03/25/07
Agreed, Good Drama Potential  blunderdog | 03/22/07
Great post Blunderdog  marty@... | 03/23/07
Think again...  metalcrit | 03/22/07
MS or Google buying them thats funny  jfp | 03/23/07
Thinking again about theft...?  idea-catalyst | 03/23/07
it was a TRAP!!!  mandodanda@... | 03/22/07
Something' doesn't sound right  John Zern | 03/22/07
Oracle server logs are worthless, they need to have ISP server logs  georgeou | 03/22/07
Message has been deleted.  jerryleecooper | 03/22/07
For the love of...  darcyfreak | 03/23/07
The Fault of the Young  blunderdog | 03/23/07
linux and the devil  llval@... | 03/23/07
WTF is this gentleman serious...?  c_vanwinkle1951@... | 03/23/07
9.5 +/- .001  osreinstall | 03/23/07
THE ART OF TOTAL WAR  zdnet@... | 03/22/07
Yes  darcyfreak | 03/23/07
It's called Industrial Espionage, and is *very* common.  kraterz | 03/22/07
A good reason to switch to SAP  rhon@... | 03/23/07
Defining the limits  Ivan21 | 03/23/07
Did SAP customers allow logon info to be used?  gregbakker | 03/23/07
What about the customers?  sysop-dr | 03/23/07
Is Oracle learning at SCO's knee?  wolf_z | 03/23/07
SAP=stop all production  AZson | 03/23/07
I reguarlly spider trees of websites,  thetruth_z | 03/23/07
This will be good.  Jim Rodgers | 03/23/07
George is right.  Jim Rodgers | 03/23/07
What if SAP signed up for an account legally?  georgeou | 03/23/07
Doors unlocked and the keys in the ignition?  jc williams | 03/23/07
we need a law giving customers some rights  brad@... | 03/23/07
not "a who's who of corporate america"  johnscar@... | 03/23/07
Ho Hum....  john.rauscher@... | 03/23/07
yeah and snowhite lived happily ever after in thornred castle lalaland  llval@... | 03/23/07
sorry was meant to reply to msg not story - correction  llval@... | 03/23/07
Beat the street  barmon777 | 03/24/07
give your head a shake  jojo26 | 03/27/07
ebay post for TomorrowNow...  jojo26 | 03/27/07
Worthwhile Downloads  trevorhunter@... | 03/29/07
RE: Oracle sues SAP; alleges 'corporate theft on a grand scale'  ujhrdngjk | 08/12/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement
Click Here

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads