# SAP Security Review and Audit - ECC, S/4HANA, BTP pentests | SNOK

> SAP security review: configuration, authorisations and SAP Security Baseline, plus penetration testing of ECC, S/4HANA, HANA and BTP. CVSS report and fix plan.

- Source: https://snok.ai/en/offer/sap-security/sap-penetration-testing/

---

# SAP security review, audit and penetration testing

An SAP security review that leaves production untouched, plus specialist penetration testing - ECC, S/4HANA, HANA, BTP, Fiori, HCM. A report with CVSS scoring, a remediation plan and the option of a retest. Evidence of due diligence for the board and auditors.

## What your organisation gains

### A picture of the current state before any testing

An SAP security review produces an ordered list of deviations from the SAP Security Baseline, with priorities. Your team gets a starting point for decisions: what to fix immediately, what needs a project, and what is worth confirming with a penetration test.

### Evidence of due diligence

Regular security testing of critical systems is expected by auditors, boards and regulators. An SAP penetration test allows an organisation to document that it actively identifies and mitigates risks in its SAP environment.

### Finding weaknesses before an attacker does

SAP systems support critical financial, logistics, production and HR processes. Penetration testing uncovers vulnerabilities in authorisations, integrations, ABAP code, and HANA, Fiori and BTP configuration before they become part of a real incident.

### A concrete, prioritised remediation plan

The report is not simply a list of findings. Every risk is described in terms of business impact, criticality, remediation priority and a recommended action for the SAP, Basis, Security or Development teams.

### Retesting after remediation

After fixes are implemented, we verify that vulnerabilities have been effectively removed. Without a retest, a penetration test easily becomes a one-off report rather than a genuine part of the security improvement process.

### A lower barrier to entry than a full pentest

A review needs no test environment, no maintenance window and no sign-off for offensive activity, so the decision to run one comes faster. We keep the penetration test for the point where basic configuration is already in order.

### A baseline for every subsequent review

We compare each review with the previous one, so you can see which deviations are gone, which came back after landscape changes and which are still awaiting a decision. SAP security stops being a snapshot from a single day.

## What we deliver on this project

### SAP security review

We check profile parameters, SNC and encryption settings, RFC connections and their authorisations, standard accounts, patch levels and outstanding SAP security notes, and compliance with the SAP Security Baseline. The result is a list of deviations with a severity rating and a remediation order.

### RFC connection and integration review

We look separately at RFC destinations, the authorisations of technical users, trust relationships between systems, and gateway and message server access control lists. This is the most common route for moving between SAP systems in a landscape.

### SAP ECC and S/4HANA penetration testing

We test authorisations, custom ABAP, RFC, IDoc, transport management, security configuration and Segregation of Duties conflicts. Scope can include whitebox, greybox or blackbox testing.

### SAP HANA and BTP penetration testing

We check SAP HANA vulnerabilities, SQL injection scenarios, BTP service configuration, the identity provider, SAP Cloud Connector and API integrations.

### SAP Fiori and Portal penetration testing

We test SAP Fiori, SAP Portal and UI5 applications against the OWASP Top 10 and SAP-specific vectors. Scope includes JWT, CSRF, SAP Personas and vulnerabilities in custom user interfaces, among others.

### SAP Code Vulnerability Analyzer

We scan custom ABAP code for vulnerabilities such as SQL injection, command injection, path traversal, hardcoded credentials and broken access control.

### SoD and authorisation audit

We identify Segregation of Duties conflicts, excessive privileges, superuser profiles and risks associated with SAP_ALL and critical administrative transactions.

### Report, remediation and retest

We deliver a report with risk assessment, CVSS scoring, vulnerability descriptions, proof of exploit, a remediation plan and recommendations for the teams responsible for SAP. After fixes are implemented, we can carry out a retest.

## How we deliver projects in this area

An SAP security review runs on data read from the system: parameters, roles and authorisations, RFC connections, patch levels and interface configuration. We take no offensive action, so the review also covers production systems. The outcome is a report listing deviations from the SAP Security Baseline, the severity of each one and the order in which to fix them.

An SAP penetration test begins by defining the scope: the systems in scope, the test type - whitebox, greybox or blackbox - and the business and audit objectives.

We then carry out reconnaissance and map the attack surface. We analyse entry points, integrations, roles, authorisations, interfaces, code and the technical configuration of the SAP environment.

During the testing phase we verify vulnerabilities, the possibility of privilege escalation, access to test data, integration risks and the business impact of identified weaknesses.

After testing, we prepare a report containing proof of exploit, CVSS scoring, a remediation plan, remediation priorities and recommended actions. The entire engagement follows OWASP, the SAP Pentest Framework and PTES.

After fixes are implemented, we can carry out a retest to confirm that the remediation was effective.

Technology stack

Partnerships backed by our team's certifications. Full authorisation for delivery and support.

## Where we have delivered similar solutions

Bank in the financial sector

S/4HANA penetration test ahead of go-live, a report for the Polish Financial Supervision Authority (KNF), and a retest following remediation.

Critical infrastructure operator

ECC and HANA penetration test ahead of an NIS2 audit, concluded with a prioritised remediation plan.

Industrial manufacturer

An annual cycle of SAP penetration tests across three countries, including regular progress reviews and verification of fix effectiveness.

## FAQ - SAP Security Review and Pentests

How does an SAP security review differ from an SAP penetration test?+

A review answers the question of how the environment is configured: we read parameters, authorisations, RFC connections, patch levels and SAP Security Baseline compliance, with no offensive action. A penetration test answers the question of what can be done with it: a controlled attack confirms which deviations are genuinely exploitable. The review is faster and safe for production; the test provides proof that an attack is feasible.

What does an SAP security review cover?+

Profile parameters and authentication settings, communication encryption and SNC, RFC connections together with the authorisations of technical users, standard accounts and default passwords, critical authorisations and Segregation of Duties conflicts, patch levels and outstanding SAP security notes, and the configuration of interfaces and integrations. We map all of it against the SAP Security Baseline.

Review or penetration test - where should we start?+

When an organisation has no current picture of its SAP systems, we start with a review: it costs less, leaves production untouched and usually surfaces a dozen or so things to fix straight away. A penetration test delivers most value once basic configuration hygiene is in place, or when an auditor or regulator expects proof that an attack is feasible.

How does an SAP penetration test differ from a classic application pentest?+

An SAP penetration test requires familiarity with platform specifics: transactions, SU01/PFCG authorisations, RFC, IDoc, ABAP, SAP HANA SQL, Fiori and integrations with external systems. A classic web application pentest typically does not cover these vectors.

How long does an SAP penetration test take?+

A standard test of a single system, such as ECC or S/4HANA, typically involves 3-4 weeks of testing plus 1-2 weeks for reporting. For a full, multi-system SAP landscape, a project usually takes 6-10 weeks.

Can an SAP penetration test disrupt production?+

It should not, if the scope and environment are properly planned. By default we work in a QA or Pre-Production environment configured to mirror production. Production testing is carried out only with the client's consent and in non-disruptive mode.

Does penetration testing support NIS2 compliance?+

Yes. SAP penetration testing can support NIS2 compliance in the area of regularly assessing the security of critical systems. A report with risk assessment, CVSS scoring, a remediation plan and a retest can serve as evidence of due diligence for the board, an internal audit or a regulator.
