External & Perimeter Testing
We probe internet-exposed SAP services, Fiori, Web Dispatcher, exposed RFC/gateway, and routers, to identify what an unauthenticated attacker can reach and exploit.
Your SAP landscape runs the business. Monitoring tools flag misconfigurations they cannot exploit. IntegSec's offensive team proves the real attack paths through S/4HANA, NetWeaver, RFC, Fiori, and HANA, then shows what an insider could actually do to your vendor master and your payment run.
Led by an offensive-security team whose founder holds CISSP, OSCP, and OSCE, with two decades breaking into enterprise systems at IBM X-Force Red, Trustwave SpiderLabs, and IntegSec.
Not a scanner reselling a dashboard. Experienced operators manually chain misconfigurations into proven attack paths a tool will never produce.
Basis, ABAP, and protocol-level knowledge (RFC, Gateway, HANA) that generic web pentesters simply do not have.
SAP systems hold your financials, HR data, supply chain, and intellectual property. That concentration of value, combined with deep customization and a specialized attack surface most testers don't understand, makes ERP a prime target. SAP flaws now appear in CISA's Known Exploited Vulnerabilities Catalog, actively used in real attacks.
RFC, ICF, the SAP Gateway, Message Server, and SAProuterare protocols most pentesters never touch. Unknown surfacemeans unfound vulnerabilities, until someone else finds them.
Default accounts like SAP*, DDIC, and EARLYWATCH, weakprofile parameters, and open gateway ACLs routinely surviveinto production, handing attackers privileged footholds.
Years of custom code, directory traversal in Z-programs, andinjection flaws ship through the transport system with littlesecurity review, expanding your exposure with every release.
Moves to S/4HANA, RISE with SAP, BTP, and Fiori/ODatareshape the perimeter. Misconfigured trust, exposed ODataservices, and integration flaws open new paths into critical systems.
The realistic worst case is not root on the application server. Itis a payment to an attacker-controlled bank account, madethrough entirely legitimate transactions, by a user granted onerole too many. A test that stops at platform compromise never sees it.
DEV, QAS, PRD, Solution Manager, BW, and PI/PO are boundtogether by trusted RFC, shared transports, and reusable SSOtickets. A finding in a sandbox is often a production finding,and Solution Manager is usually the strongest path intoeverything it manages.
Real SAP penetration testing means going deep on components unique to the platform. Our team assesses the full stack, from network-facing services down to custom ABAP and the HANA database, the way an actual attacker or malicious insider would.
RFC, Message Server, Gateway ACLs, SAProuter
ICF services, Fiori, OData, SAP Web Dispatcher
Injection, traversal, missing auth checks
HANA, database privileges, secure store
Profile params, SoD, privilege escalation
FI/AP, MM, SD, HCM fraud paths
Trusted RFC, transports, Solution Manager
SM35, LSMW, SE16N, Winshuttle bypasses
DIAG capture, SNC, workstation artifacts
Audit log, SIEM, what your SOC missed
We probe internet-exposed SAP services, Fiori, Web Dispatcher, exposed RFC/gateway, and routers, to identify what an unauthenticated attacker can reach and exploit.
Starting from a low-privilege account, we chain misconfigurations, weak authorizations, and standard-user weaknesses to demonstrate real privilege escalation to SAP_ALL.
We evaluate profile parameters, gateway and message server security, secure network communication, and patch levels against SAP and DSAG security baselines.
Findings are risk-ranked by real business impact (access to financial postings, master data, or PII) so remediation targets what actually threatens the business first.
We verify exposure to the SAP flaws confirmed as exploited in the wild, checked against your actual component and patch levels rather than inferred from a banner.
We read business data directly by SQL and show it produces no entry in your SAP Security Audit Log. It takes minutes, and it changes how most teams think about their SAP controls.
Every entry below appears in CISA's Known Exploited Vulnerabilities catalog, meaning confirmed use in real attacks rather than a theoretical CVSS score. We check your exposure to each one.
SAP Security Notes Patch Day| CVE | COMPONENTS | What It Gives an Attacker | ADDED TO DEV |
|---|---|---|---|
|
CVE-2025-31324
RANSOMWARE |
NetWeaver Visual Composer | Unrestricted file upload leading to remote code execution, with no authentication | Apr 2025 |
| CVE-2022-22536 | ICM & Web Dispatcher (ICMAD) | HTTP request smuggling leading to session hijack and full system compromise | Aug 2022 |
| CVE-2020-6287 | AS Java, LM Configuration Wizard (RECON) | Missing authentication on a critical function, allowing creation of an administrative user | Nov 2021 |
| CVE-2020-6207 | Solution Manager (EEM) | Missing authentication leading to code execution on every managed system in the landscape | Nov 2021 |
|
CVE-2018-2380
RANSOMWARE |
Customer Relationship Management | Path traversal leading to remote code execution | Nov 2021 |
| CVE-2010-5326 | AS Java Invoker Servlet | Authentication bypass leading to remote code execution | Nov 2021 |
This is the question a platform-only test never answers, and the one your audit committee actually asks. We run agreed fraud scenarios end to end against test master data, with a written stop line, and show which control should have caught each one.
Who can change a vendor's bank details, and can they do it through SE16N or a BAPI when the transaction is locked down? Is sensitive-field dual control actually enforced? Can the same person edit an F110 payment proposal and run the payment? We test alternative payee and one-time vendor routes too, which redirect money without touching the vendor's own record.
We test conflicts against the whole role catalogue, not just our own account, and report the smallest role that enables each one and how many users hold it. A conflict held by two named people is a very different risk from one held by four hundred. Where you license GRC Access Control, we run your ruleset and report gaps in both directions.
Release strategy bypass by raising a PO after approval. Goods receipt and invoice verification held by one user, collapsing the three-way match. Service entry sheets, where there is no physical goods receipt to check. Tolerance keys set so wide the match can never fail.
HR runs on a second, parallel authorization model that ordinary role analysis does not see. We test hiring a fictitious employee end to end, IT0009 bank-detail changes, ESS self-service changes with no approval or notification, and whether P_ABAP is quietly disabling HR checks inside reports.
Offensive expertise applied to the ERP that runs your business. We don't hand you a scanner dump, we demonstrate exploitable attack paths and how to close them.
Expert-led, manual penetration testing that simulates real-world external attackers and malicious insiders against your SAP landscape.
What You Get:Documented attack chains with proof-of-exploit, business-impact risk ratings, and prioritized, Basis-ready remediation guidance.
A deep review of your SAP security posture against platform baselines, ideal ahead of go-live, an S/4HANA migration, or an audit.
Audit & Compliance Support: Evidence and reporting that support SOX ITGC, PCI DSS, ISO 27001, and internal audit, aligned to SAP and DSAG security guidelines.
The review that makes this an ERP penetration test rather than a NetWeaver one. Run with a functional counterpart, against test master data, inside written stop lines.
Written for Two Audiences: Fraud scenario walkthroughs your finance and internal audit teams can read directly, alongside the technical detail your Basis team needs.
Because the landscape is the real unit of scope. We test whether a foothold anywhere becomes control everywhere, then measure what your SOC actually saw.
What You Get: Evidence and reporting that support SOX ITGC, PCI DSS, ISO 27001, and internal audit, aligned to SAP and DSAG security guidelines.
Our testers combine offensive security depth with real SAP knowledge: Basis, ABAP, and the protocols that make SAP its own discipline. SAP work led by people who have lived in these systems.
Monitoring platforms flag configuration drift. They do not exploit it. We do. Every finding is a hand-built, proven attack chain, ranked by real business impact, so your team fixes what an attacker would actually use.
We scope carefully and coordinate with your Basis and security teams, testing safely against production or production-like landscapes without interrupting operations.
Clear technical detail for your engineers plus an executive summary and evidence your auditors and leadership can act on immediately.
Common questions from security, Basis, and audit teams evaluating an SAP penetration test.
Offensive security testing focused on the SAP-specific attack surface: RFC and ICF services, the SAP Gateway and Message Server, SAP GUI and Fiori, OData APIs, custom ABAP, transport management, and the HANA database. Rather than a generic scan, it simulates real attackers and insiders to uncover exploitable paths to your most business-critical data.
Offensive security testing focused on the SAP-specific attack surface: RFC and ICF services, the SAP Gateway and Message Server, SAP GUI and Fiori, OData APIs, custom ABAP, transport management, and the HANA database. Rather than a generic scan, it simulates real attackers and insiders to uncover exploitable paths to your most business-critical data.
Offensive security testing focused on the SAP-specific attack surface: RFC and ICF services, the SAP Gateway and Message Server, SAP GUI and Fiori, OData APIs, custom ABAP, transport management, and the HANA database. Rather than a generic scan, it simulates real attackers and insiders to uncover exploitable paths to your most business-critical data.
Offensive security testing focused on the SAP-specific attack surface: RFC and ICF services, the SAP Gateway and Message Server, SAP GUI and Fiori, OData APIs, custom ABAP, transport management, and the HANA database. Rather than a generic scan, it simulates real attackers and insiders to uncover exploitable paths to your most business-critical data.
Offensive security testing focused on the SAP-specific attack surface: RFC and ICF services, the SAP Gateway and Message Server, SAP GUI and Fiori, OData APIs, custom ABAP, transport management, and the HANA database. Rather than a generic scan, it simulates real attackers and insiders to uncover exploitable paths to your most business-critical data.
Offensive security testing focused on the SAP-specific attack surface: RFC and ICF services, the SAP Gateway and Message Server, SAP GUI and Fiori, OData APIs, custom ABAP, transport management, and the HANA database. Rather than a generic scan, it simulates real attackers and insiders to uncover exploitable paths to your most business-critical data.
Offensive security testing focused on the SAP-specific attack surface: RFC and ICF services, the SAP Gateway and Message Server, SAP GUI and Fiori, OData APIs, custom ABAP, transport management, and the HANA database. Rather than a generic scan, it simulates real attackers and insiders to uncover exploitable paths to your most business-critical data.
IntegSec provides specialized offensive security testing across the platforms and industries that run your business.
Penetration testing for E-Business Suite, PeopleSoft, JD Edwards, and Fusion Cloud ERP.
Testing for D365 Finance & Operations, Business Central, legacy AX/NAV/GP, and Power Platform.
Penetration testing and security reviews for Salesforce orgs, Apex, and Experience Cloud.
PCI DSS compliance and security testing for banks and financial institutions.
Find the exploitable paths into your SAP landscape before an attacker does. Book a 30-minute scoping call with IntegSec's ERP security experts to define the right test for your environment. No prep needed.