<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1950087345534883&amp;ev=PageView&amp;noscript=1">
Skip to content

SAP & ERP Security

SAP Penetration Testing .

Prove the Attack Path Before Attackers Do.

Your SAP landscape runs the business. Monitoring tools flag misconfigurations they cannot exploit. IntegSec's offensive team proves the real attack paths through S/4HANA, NetWeaver, RFC, Fiori, and HANA, then shows what an insider could actually do to your vendor master and your payment run.

6295907141639652363-128 1

Decades on the Offense

Led by an offensive-security team whose founder holds CISSP, OSCP, and OSCE, with two decades breaking into enterprise systems at IBM X-Force Red, Trustwave SpiderLabs, and IntegSec.

10217013321529659193-128 1

Real Human Pentesters

Not a scanner reselling a dashboard. Experienced operators manually chain misconfigurations into proven attack paths a tool will never produce.

882803 1

SAP-Specific Depth

Basis, ABAP, and protocol-level knowledge (RFC, Gateway, HANA) that generic web pentesters simply do not have.

Why SAP Is a High-Value Target

SAP systems hold your financials, HR data, supply chain, and intellectual property. That concentration of value, combined with deep customization and a specialized attack surface most testers don't understand, makes ERP a prime target. SAP flaws now appear in CISA's Known Exploited Vulnerabilities Catalog, actively used in real attacks.

Vector-1

A Surface Generic Testers Miss

RFC, ICF, the SAP Gateway, Message Server, and SAProuterare protocols most pentesters never touch. Unknown surfacemeans unfound vulnerabilities, until someone else finds them.

Insecure Defaults & Standard Users

Default accounts like SAP*, DDIC, and EARLYWATCH, weakprofile parameters, and open gateway ACLs routinely surviveinto production, handing attackers privileged footholds.

Custom ABAP & Transport Risk

Years of custom code, directory traversal in Z-programs, andinjection flaws ship through the transport system with littlesecurity review, expanding your exposure with every release.

Cloud & S/4HANA Migration Exposure

Moves to S/4HANA, RISE with SAP, BTP, and Fiori/ODatareshape the perimeter. Misconfigured trust, exposed ODataservices, and integration flaws open new paths into critical systems.

The Exploit Is a Business Transaction

The realistic worst case is not root on the application server. Itis a payment to an attacker-controlled bank account, madethrough entirely legitimate transactions, by a user granted onerole too many. A test that stops at platform compromise never sees it.

One System Is Not the Scope

DEV, QAS, PRD, Solution Manager, BW, and PI/PO are boundtogether by trusted RFC, shared transports, and reusable SSOtickets. A finding in a sandbox is often a production finding,and Solution Manager is usually the strongest path intoeverything it manages.

The SAP Attack Surface We Test

Real SAP penetration testing means going deep on components unique to the platform. Our team assesses the full stack, from network-facing services down to custom ABAP and the HANA database, the way an actual attacker or malicious insider would.

RFC & Gateway

RFC, Message Server, Gateway ACLs, SAProuter

Web & ICF

ICF services, Fiori, OData, SAP Web Dispatcher

Custom ABAP

Injection, traversal, missing auth checks

HANA & DB

HANA, database privileges, secure store

Auth & Roles

Profile params, SoD, privilege escalation

Business Controls

FI/AP, MM, SD, HCM fraud paths

Landscape Trust

Trusted RFC, transports, Solution Manager

Mass-Data Tools

SM35, LSMW, SE16N, Winshuttle bypasses

Client & GUI

DIAG capture, SNC, workstation artifacts

Detection

Audit log, SIEM, what your SOC missed

External & Perimeter Testing

We probe internet-exposed SAP services, Fiori, Web Dispatcher, exposed RFC/gateway, and routers, to identify what an unauthenticated attacker can reach and exploit.

Authenticated & Insider Simulation

Starting from a low-privilege account, we chain misconfigurations, weak authorizations, and standard-user weaknesses to demonstrate real privilege escalation to SAP_ALL.

Configuration & Baseline Review

We evaluate profile parameters, gateway and message server security, secure network communication, and patch levels against SAP and DSAG security baselines.

Business Impact Validation

Findings are risk-ranked by real business impact (access to financial postings, master data, or PII) so remediation targets what actually threatens the business first.

Known-Exploited Vulnerability Sweep

We verify exposure to the SAP flaws confirmed as exploited in the wild, checked against your actual component and patch levels rather than inferred from a banner.

Database-Layer Audit Bypass

We read business data directly by SQL and show it produces no entry in your SAP Security Audit Log. It takes minutes, and it changes how most teams think about their SAP controls.

SAP Vulnerabilities Confirmed Exploited in the Wild

Every entry below appears in CISA's Known Exploited Vulnerabilities catalog, meaning confirmed use in real attacks rather than a theoretical CVSS score. We check your exposure to each one.

SAP Security Notes Patch Day
CVE COMPONENTS What It Gives an Attacker ADDED TO DEV
CVE-2025-31324
RANSOMWARE
NetWeaver Visual Composer Unrestricted file upload leading to remote code execution, with no authentication Apr 2025
CVE-2022-22536 ICM & Web Dispatcher (ICMAD) HTTP request smuggling leading to session hijack and full system compromise Aug 2022
CVE-2020-6287 AS Java, LM Configuration Wizard (RECON) Missing authentication on a critical function, allowing creation of an administrative user Nov 2021
CVE-2020-6207 Solution Manager (EEM) Missing authentication leading to code execution on every managed system in the landscape Nov 2021
CVE-2018-2380
RANSOMWARE
Customer Relationship Management Path traversal leading to remote code execution Nov 2021
CVE-2010-5326 AS Java Invoker Servlet Authentication bypass leading to remote code execution Nov 2021

Can Your Business Be Defrauded?

This is the question a platform-only test never answers, and the one your audit committee actually asks. We run agreed fraud scenarios end to end against test master data, with a written stop line, and show which control should have caught each one.

question-mark-icon-F5eC926281 1

The Payment Path

Who can change a vendor's bank details, and can they do it through SE16N or a BAPI when the transaction is locked down? Is sensitive-field dual control actually enforced? Can the same person edit an F110 payment proposal and run the payment? We test alternative payee and one-time vendor routes too, which redirect money without touching the vendor's own record.

Segregation of Duties, Quantified

We test conflicts against the whole role catalogue, not just our own account, and report the smallest role that enables each one and how many users hold it. A conflict held by two named people is a very different risk from one held by four hundred. Where you license GRC Access Control, we run your ruleset and report gaps in both directions.

Procurement & Three-Way Match

Release strategy bypass by raising a PO after approval. Goods receipt and invoice verification held by one user, collapsing the three-way match. Service entry sheets, where there is no physical goods receipt to check. Tolerance keys set so wide the match can never fail.

Payroll & HR

HR runs on a second, parallel authorization model that ordinary role analysis does not see. We test hiring a fictitious employee end to end, IT0009 bank-detail changes, ESS self-service changes with no approval or notification, and whether P_ABAP is quietly disabling HR checks inside reports.

How IntegSec Tests SAP

Offensive expertise applied to the ERP that runs your business. We don't hand you a scanner dump, we demonstrate exploitable attack paths and how to close them.

SAP Penetration Testing

Expert-led, manual penetration testing that simulates real-world external attackers and malicious insiders against your SAP landscape.

  • External and internal network penetration testing
  • RFC, Gateway, Message Server, and SAProuter exploitation
  • Fiori, ICF, and OData web application testing
  • Privilege escalation and authorization abuse (path to SAP_ALL)
  • Custom ABAP code review for injection and traversal

What You Get:Documented attack chains with proof-of-exploit, business-impact risk ratings, and prioritized, Basis-ready remediation guidance.

ERP Security & Configuration Assessment

A deep review of your SAP security posture against platform baselines, ideal ahead of go-live, an S/4HANA migration, or an audit.

  • Profile parameter and secure configuration review
  • Standard user and default credential hardening
  • Segregation of Duties (SoD) and role/authorization analysis
  • Patch level and SAP Security Note gap assessment
  • S/4HANA, BTP, and RISE with SAP readiness review

Audit & Compliance Support: Evidence and reporting that support SOX ITGC, PCI DSS, ISO 27001, and internal audit, aligned to SAP and DSAG security guidelines.

Business Control & Fraud Path Review

The review that makes this an ERP penetration test rather than a NetWeaver one. Run with a functional counterpart, against test master data, inside written stop lines.

  • Vendor master, bank detail, and payment run (F110) control testing
  • Procurement release strategy and three-way-match tolerance abuse
  • Order-to-cash: credit limits, pricing overrides, credit memos
  • HCM and payroll, including the separate HR authorization model
  • Cross-module SoD matrix with affected user population per conflict

Written for Two Audiences: Fraud scenario walkthroughs your finance and internal audit teams can read directly, alongside the technical detail your Basis team needs.

Landscape, Assumed Breach & Detection

Because the landscape is the real unit of scope. We test whether a foothold anywhere becomes control everywhere, then measure what your SOC actually saw.

  • Trusted RFC, shared transport directories, and SSO ticket reuse
  • Sandbox and QAS to production escalation paths
  • Solution Manager as a path into every managed system
  • Database-layer bypass of SAP authorization controls
  • Detection assessment: our action log versus your alerts

What You Get: Evidence and reporting that support SOX ITGC, PCI DSS, ISO 27001, and internal audit, aligned to SAP and DSAG security guidelines.

Let’s Talk
WHY CHOOSE US

 Why Teams Choose IntegSec for SAP 

Featured icon-2
Deep SAP Expertise

Our testers combine offensive security depth with real SAP knowledge: Basis, ABAP, and the protocols that make SAP its own discipline. SAP work led by people who have lived in these systems.

Featured icon (1)-2
Real Attack Paths, Not Scan Noise

Monitoring platforms flag configuration drift. They do not exploit it. We do. Every finding is a hand-built, proven attack chain, ranked by real business impact, so your team fixes what an attacker would actually use.

Featured icon (2)-2
Non-Disruptive by Design

We scope carefully and coordinate with your Basis and security teams, testing safely against production or production-like landscapes without interrupting operations.

Featured icon (3)-2
Audit-Ready Reporting

Clear technical detail for your engineers plus an executive summary and evidence your auditors and leadership can act on immediately.

FAQs-amico 1-3

SAP Penetration Testing FAQ

Common questions from security, Basis, and audit teams evaluating an SAP penetration test.

  • Offensive security testing focused on the SAP-specific attack surface: RFC and ICF services, the SAP Gateway and Message Server, SAP GUI and Fiori, OData APIs, custom ABAP, transport management, and the HANA database. Rather than a generic scan, it simulates real attackers and insiders to uncover exploitable paths to your most business-critical data.

  • Offensive security testing focused on the SAP-specific attack surface: RFC and ICF services, the SAP Gateway and Message Server, SAP GUI and Fiori, OData APIs, custom ABAP, transport management, and the HANA database. Rather than a generic scan, it simulates real attackers and insiders to uncover exploitable paths to your most business-critical data.

  • Offensive security testing focused on the SAP-specific attack surface: RFC and ICF services, the SAP Gateway and Message Server, SAP GUI and Fiori, OData APIs, custom ABAP, transport management, and the HANA database. Rather than a generic scan, it simulates real attackers and insiders to uncover exploitable paths to your most business-critical data.

  • Offensive security testing focused on the SAP-specific attack surface: RFC and ICF services, the SAP Gateway and Message Server, SAP GUI and Fiori, OData APIs, custom ABAP, transport management, and the HANA database. Rather than a generic scan, it simulates real attackers and insiders to uncover exploitable paths to your most business-critical data.

  • Offensive security testing focused on the SAP-specific attack surface: RFC and ICF services, the SAP Gateway and Message Server, SAP GUI and Fiori, OData APIs, custom ABAP, transport management, and the HANA database. Rather than a generic scan, it simulates real attackers and insiders to uncover exploitable paths to your most business-critical data.

  • Offensive security testing focused on the SAP-specific attack surface: RFC and ICF services, the SAP Gateway and Message Server, SAP GUI and Fiori, OData APIs, custom ABAP, transport management, and the HANA database. Rather than a generic scan, it simulates real attackers and insiders to uncover exploitable paths to your most business-critical data.

  • Offensive security testing focused on the SAP-specific attack surface: RFC and ICF services, the SAP Gateway and Message Server, SAP GUI and Fiori, OData APIs, custom ABAP, transport management, and the HANA database. Rather than a generic scan, it simulates real attackers and insiders to uncover exploitable paths to your most business-critical data.

Explore More Security Solutions

IntegSec provides specialized offensive security testing across the platforms and industries that run your business.

Group 2085662916-3

Oracle ERP Security

Penetration testing for E-Business Suite, PeopleSoft, JD Edwards, and Fusion Cloud ERP.

Group 2085662916 (1)-3

Microsoft Dynamics Security

Testing for D365 Finance & Operations, Business Central, legacy AX/NAV/GP, and Power Platform.

Group 2085662916 (2)-3

Salesforce Security

Penetration testing and security reviews for Salesforce orgs, Apex, and Experience Cloud.

Group 2085662916 (3)-3

Financial Services

PCI DSS compliance and security testing for banks and financial institutions.

Test the System That Runs Your Business

Find the exploitable paths into your SAP landscape before an attacker does. Book a 30-minute scoping call with IntegSec's ERP security experts to define the right test for your environment. No prep needed.