The target value: SAP as the primary database of record
SAP ERP landscapes (including NetWeaver, ABAP stacks, and S/4HANA instances) manage core business processes, financial data, supplier databases, and corporate intellectual property. Because these systems are historically deployed deep within internal networks, security teams often operate under the assumption of isolation. Today, modern business needs (like Fiori web interfaces, API-driven customer portals, and integration with third-party logistics apps) expose these systems directly to the web.
The assumption of isolation is exactly what recent attacks have punished. In April 2025, researchers at Onapsis and Rapid7 confirmed active, in-the-wild exploitation of CVE-2025-31324, a maximum-severity (CVSS 10.0) flaw in the SAP NetWeaver Visual Composer Metadata Uploader. A missing authorization check let unauthenticated attackers upload arbitrary files to an internet-facing endpoint and achieve remote code execution, and threat actors used it to plant web shells inside production SAP systems. A related flaw, CVE-2025-42999, extended the exposure. These were not lab findings — they were being exploited before many organisations even knew the endpoint was reachable. That is precisely the scenario SAP penetration testing is built to catch: an exposed component, introduced or left enabled, that an attacker can reach from the open internet.
Critical SAP vulnerability categories
- SAP ICF Service Exposure: The Internet Communication Framework (ICF) exposes transactional systems via HTTP. Misconfigured handlers allow unauthorized users to probe business logic.
- Open RFC/SOAP Gateways: Insecure Remote Function Call (RFC) destinations or open routers allow adversaries to bypass authentication and execute remote administrative functions.
- ABAP Authorization Misconfigurations: Custom ABAP programs with missing or weak authority checks (`AUTHORITY-CHECK`) allow users to escalate privileges or retrieve restricted table data.
- Default Credentials & Profiles: Out-of-the-box SAP client parameters (such as SAP*, DDIC, or default master keys) that are left unrotated provide quick compromise paths.
What a read-only SAP penetration testing pipeline checks
Effective SAP penetration testing does not require intrusive exploitation to be useful. Most of the highest-impact SAP exposures are configuration and reachability problems that a careful, passive assessment can surface without touching a single business record. AssurePort's SAP Pentest engine works through a structured set of checks:
- Internet Communication Framework (ICF) surface: enumerating which ICF services and handlers are active and reachable, and flagging the diagnostic and administrative services that should never be exposed externally.
- Gateway and RFC exposure: checking for open SAP Gateway access (
reg_info/sec_infoACLs) and insecure RFC destinations that can forward requests or bypass authentication. - ABAP authorization hygiene: identifying custom programs and function modules that lack an explicit
AUTHORITY-CHECK— the pattern behind most privilege-escalation paths in custom code. - Standard accounts and profile parameters: detecting default users such as SAP*, DDIC, and EARLYWATCH left with well-known credentials, and reviewing security-relevant profile parameters (login policy, password hashing, gateway security).
- Patch and Security Note posture: mapping active components against SAP's monthly Security Note releases, so that a component exposed to a known critical advisory is surfaced rather than silently carried into the next audit cycle.
Each finding is delivered with a severity rating, the affected component, and remediation guidance — the same structured format that ISO 27001 and DORA evidence workflows expect from any penetration test. The goal is coverage that is broad enough to be useful and safe enough to run against production without an availability risk.
The danger of check-box audits: The 365-day gap
Most enterprises audit SAP configurations during annual compliance exercises. In between audits, engineers modify roles, apply hotfixes, enable diagnostic endpoints, and change network rules. A vulnerability introduced on a Tuesday will remain active until the next audit cycle. For highly regulated enterprises, this latency violates continuous monitoring expectations defined by frameworks like ISO 27001 and DORA.
AssurePort SAP Pentest operates a safe, non-destructive audit pipeline. It maps active software components, tests endpoint security, and flags missing authorization checks passively, delivering continuous visibility without impacting database workloads.
Safe black-box testing: Unlike intrusive exploit tools, AssurePort evaluates SAP configurations safely. Credentials are never written, tables are never modified, and RFC connections are limited to passive queries, protecting the operational availability of production databases.
SAP penetration testing belongs in continuous monitoring
ERP systems change constantly, and each change can quietly re-open an attack path. A transport is imported, a Fiori app is published, an RFC destination is added for a new integration — any of these can expose the enterprise core between two annual reviews. This is why SAP penetration testing increasingly sits inside a continuous monitoring programme rather than a once-a-year checklist.
The regulatory direction reinforces the shift. ISO 27001:2022 Annex A 8.8 asks for a systematic, ongoing vulnerability management process, and DORA Article 10 requires continuous vulnerability management for EU financial entities. A single annual SAP review satisfies neither in spirit: it produces a point-in-time artefact that is already stale by the time it is filed. Continuous, read-only SAP penetration testing produces a timestamped finding log that reflects the system as it actually is today — exactly what an auditor, insurer, or procurement team now asks to see.
Frequently Asked Questions
What is SAP penetration testing?
SAP penetration testing is the security assessment of an SAP landscape — NetWeaver, ABAP, S/4HANA, and Fiori — to find exploitable weaknesses such as exposed ICF services, insecure RFC gateways, missing ABAP authority checks, and unrotated default credentials. It treats the ERP as an internet-facing attack surface rather than assuming network isolation.
Is SAP penetration testing safe to run against production?
AssurePort's SAP Pentest is read-only and non-destructive. It maps active software components, tests endpoint exposure, and flags missing authorization checks using passive queries only. Credentials are never written, tables are never modified, and RFC connections are limited to passive reads, protecting the availability of production databases.
Why can't SAP security wait for the annual audit?
Between annual audits, engineers change roles, apply hotfixes, and enable diagnostic endpoints. A vulnerability introduced on a Tuesday stays active until the next cycle. CVE-2025-31324, a CVSS 10.0 NetWeaver Visual Composer flaw, was exploited in the wild within days of disclosure — proof that annual cadence leaves too much exposure. Continuous SAP penetration testing closes that gap.
Which SAP components does the scan cover?
The SAP Pentest pipeline covers NetWeaver and its Internet Communication Framework (ICF), ABAP custom-code authority checks, RFC and SOAP gateway exposure, SAP Gateway ACLs, S/4HANA Fiori web interfaces, and default profile parameters and standard accounts such as SAP* and DDIC.
How does SAP penetration testing support ISO 27001 and DORA compliance?
ISO 27001 Annex A 8.8 and DORA Article 10 both expect continuous, evidenced vulnerability management. Continuous SAP penetration testing produces timestamped findings mapped to severity and remediation status, giving auditors current evidence rather than a point-in-time report that was accurate months ago.