Skip to main content
SAP Pentest Playbook
Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Back to homepage

SAP Pentest Playbook

_images/hackathon_logo_v2_lowres.png
_images/hackathon_logo_v2_lowres.png

A community-driven, open-source reference for penetration testing SAP systems and landscapes - practical attack vectors, tooling, and the detection and mitigation that go with them. Part of the OWASP Core Business Application Security (CBAS) project.

The Playbook consolidates knowledge that is otherwise scattered across notes, blogs, conference talks, and tribal experience into one structured, verifiable, up-to-date guide.

Authorized testing only
Every technique here is for authorized security testing, defensive hardening, and research. You must hold explicit permission to test the target system. For SAP-managed cloud environments (BTP, cloud editions), SAP approval is required before any active testing - see How to Use the Playbook. Testing without authorization is illegal.

What’s inside

  • SAP ABAP Platform - the classic AS ABAP application server (RFC, Gateway, Message Server, SSO, Secure Store, users & authorizations).
  • SAP NetWeaver Java - AS Java stack (P4/RMI, CTC, Telnet admin, SecStore, UME).
  • SAP Business Technology Platform - the cloud platform (XSUAA/identity, destinations, Cloud Foundry, Kyma, Integration Suite, service keys).
  • Other SAP Solutions - SAProuter, Web Dispatcher, Cloud Connector, HANA DB, Sybase ASE, Solution Manager, …

Start here

  • New to the Playbook? Read About the Playbook (scope, goals, what’s in and out) and How to Use It (page anatomy, methodology, safe-testing, glossary, ports).
  • Want to contribute? See Contributing - the content-quality bar, page format, and PR process.
  • Questions / feedback? Join the Discord.