An SAP security review runs on data read from the system: parameters, roles and authorisations, RFC connections, patch levels and interface configuration. We take no offensive action, so the review also covers production systems. The outcome is a report listing deviations from the SAP Security Baseline, the severity of each one and the order in which to fix them.
An SAP penetration test begins by defining the scope: the systems in scope, the test type - whitebox, greybox or blackbox - and the business and audit objectives.
We then carry out reconnaissance and map the attack surface. We analyse entry points, integrations, roles, authorisations, interfaces, code and the technical configuration of the SAP environment.
During the testing phase we verify vulnerabilities, the possibility of privilege escalation, access to test data, integration risks and the business impact of identified weaknesses.
After testing, we prepare a report containing proof of exploit, CVSS scoring, a remediation plan, remediation priorities and recommended actions. The entire engagement follows OWASP, the SAP Pentest Framework and PTES.
After fixes are implemented, we can carry out a retest to confirm that the remediation was effective.