Test the path from SAP entry point to business-critical action.
SAP security depends on controls distributed across user-facing applications, ABAP logic, roles and authorization objects, RFC destinations, interfaces and connected cloud or enterprise services. The assessment follows those relationships to determine whether an exposed or lower-privilege starting point can reach data, functions or administrative capability beyond its intended boundary.
SCOPE → DISCOVER → TEST → VALIDATE → REPORT → RETEST
Each boundary is tested independently, then examined as part of the complete path.
- 01ENTRY
- 02FIORI / ODATA
- 03ABAP / AUTH
- 04RFC / INTEGRATION
- 05BUSINESS OBJECTIVE
SAP LANDSCAPE / AUTHORIZATION PATH
ASSESSMENT BOUNDARY
What is being assessed?
The engagement boundary is defined by systems, identities, workflows and restrictions—not only a list of URLs or assets.
- In-scope SAP S/4HANA, SAP NetWeaver AS ABAP and related application components
- SAP Fiori, WebGUI, ICF and OData services included in scope
- Roles, profiles, authorization objects and separation between business functions
- RFC destinations, trust relationships, gateways and approved integration interfaces
- Custom ABAP developments, transactions and business logic where explicitly included
- SAP BTP applications, destinations, identities and cloud-to-on-premise connectivity where scoped
- Relevant configuration, exposed services and technical-user privilege paths
What Botnet tests.
Testing is manual-led and supported by appropriate tooling. Findings are manually validated before reporting. Coverage follows reachable trust decisions and agreed risk; source-code review is not implied unless explicitly scoped.
External and application entry
Reachable Fiori, OData, ICF, WebGUI and other approved HTTP-facing services, including authentication and session behavior.
Roles and authorization
Effective access across supplied business roles, transactions, services and relevant authorization objects using agreed test identities.
Custom application logic
Authorization checks, input handling and business workflows in custom ABAP or extensions when code or functionality is explicitly scoped.
RFC and integration trust
Approved RFC destinations, trusted relationships, gateway exposure and interfaces connecting SAP to SAP or non-SAP systems.
Platform and configuration
Security-relevant service exposure, technical users, administrative surfaces and configuration conditions that affect exploitability.
BTP and hybrid paths
Identity, destinations, application routes and cloud-to-on-premise trust where SAP BTP components are part of the agreed landscape.
How the work progresses.
- 01
Landscape
Confirm products, systems, clients, interfaces, ownership and production constraints.
- 02
Identity
Define supplied users, roles, technical accounts and permitted assessment perspectives.
- 03
Map
Trace Fiori/OData, ABAP, RFC, BTP and integration boundaries included in scope.
- 04
Challenge
Test selected authorization, application and trust decisions using controlled actions.
- 05
Validate
Establish impact safely, with sensitive business transactions and data-handling limits kept explicit.
- 06
Report
Map evidence to the affected SAP component, role, interface or custom control and provide an agreed re-test.
EVIDENCE + ACTION
What the customer receives.
- SAP landscape and assessment-boundary summary
- Validated technical findings with affected systems, clients, roles or interfaces
- Reproducible evidence with sensitive business data minimized
- Attack-path context across application, authorization and integration boundaries
- Prioritized remediation guidance and explicit testing limitations
- Technical readout and one re-test result for agreed remediated findings
Evidence over assumption.
01Business functions considered alongside technical entry points
02Authorization and integration paths tested as one connected landscape
03Controlled evidence designed for SAP Basis, security and application owners
04Clear distinction between observed exposure, effective privilege and validated impact
Before scoping.
Which SAP products are included?
Only the systems and components named in scope are included. S/4HANA, NetWeaver AS ABAP, Fiori/OData, BTP and connected interfaces require separate confirmation during scoping.
Does this include SAP role design or a segregation-of-duties audit?
The assessment may test effective permissions and role boundaries relevant to attack paths. A complete role redesign, governance review or segregation-of-duties audit is not implied unless separately scoped.
Can testing be performed in production?
Potentially, but production testing requires explicit restrictions, business-process exclusions, monitoring contacts and stop conditions. Higher-risk validation may need a representative non-production system.
Is custom ABAP code reviewed?
Custom code or logic can be included when the relevant programs, transactions and review method are explicitly named. Source-code review is not automatically included in an external or authenticated penetration test.
Define the target, constraints and required evidence.
An assessment request starts a scoping conversation. It does not authorize testing. Work proceeds only after scope acceptance, executed authorization/SOW and kickoff.