Skip to main content
SAP Pentest Playbook
Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Toggle Dark/Light/Auto mode Back to homepage
Edit page

About the Playbook

Disclaimer

This guide is intended for educational and research purposes only. Unauthorized access to any system is illegal and unethical. The information provided here is solely for learning and understanding security concepts, not for conducting or supporting malicious activities.

The author(s) assume no responsibility or liability for any misuse, damages, or consequences resulting from the use of this information, including but not limited to active attacks against systems.

This guide does not provide any zero-day exploits or vulnerabilities that have not already been publicly disclosed in accordance with SAP’s responsible disclosure policy.

What is the Playbook about

The SAP Pentest Playbook is a community-driven, open-source resource that documents practical techniques, tools, and methodologies for conducting penetration tests on SAP systems and landscapes.

It is part of the OWASP Core Business Application Security (CBAS) project and aims to serve as a single, reliable point of reference for security professionals, pentesters, and researchers.

The Playbook consolidates distributed, often outdated or hard-to-find knowledge into a structured and up-to-date guide that covers:

  • Well known attack vectors in SAP environments
  • Misconfigurations and “works as designed” behaviors that can be misused
  • Reconnaissance, exploitation, and post-exploitation techniques
  • Detection and mitigation considerations

Who it’s for

  • Penetration testers and red teamers assessing SAP systems, who need SAP-specific techniques rather than generic infrastructure testing.
  • SAP Basis and security teams who want to understand - and detect - how their landscape is attacked, and harden it.
  • Security researchers looking for a structured map of the SAP attack surface and where the interesting problems live.

Deep prior SAP knowledge is not assumed; core terms and conventions are introduced in How to Use the Playbook. Some familiarity with general penetration-testing concepts is expected.

Scope

In scope

  • The SAP-specific attack surface across the platforms listed on the home page - AS ABAP, AS Java, SAP Business Technology Platform (BTP), and the supporting solutions (SAProuter, Web Dispatcher, Cloud Connector, HANA DB, Sybase ASE, …)
  • Techniques a tester can reproduce in a customer-operated environment: on-premise systems and customer-managed cloud (PaaS/IaaS) such as BTP subaccounts, Cloud Foundry, Kyma, and HANA Cloud instances.
  • Publicly disclosed vulnerabilities and “works-as-designed” behaviors, always paired with detection and mitigation.

Out of scope (referenced, not reproduced)

  • Generic, non-SAP techniques - operating-system privilege escalation, Active Directory attacks, generic container/Kubernetes escapes. Where these matter to an SAP chain, the Playbook documents the SAP-specific foothold and links out to a dedicated resource (e.g. HackTricks) rather than reproducing them.
  • SAP-managed SaaS-only vulnerabilities - issues that live entirely in SAP’s own managed backend (e.g. research against a multi-tenant SaaS control plane) and cannot be reproduced or remediated by a customer. These are noted as background/context where they motivate a customer-facing test, but are not written as reproducible techniques.
  • Zero-days and non-public exploit detail. The Playbook documents only material that is already public and responsibly disclosed. See Contributing for how sensitive, exploit-heavy content is handled.

How the Playbook is organized

Content is split first by platform (the top-level sections), then within each platform by phase and page type:

  • reconnaissance/ - unauthenticated / low-touch discovery and fingerprinting for that platform.
  • known_attack_vectors/ - the core techniques: each page describes one attack vector end-to-end.
  • _objects/ and _options/ - supporting reference pages (systems, services, and reusable option/technique building blocks) that the attack-vector pages link to.

Every attack-vector page follows the same shape (Description → Risk → Options → Mitigation → Detection and Monitoring → References) so you can scan any page the same way - see How to Use the Playbook for what each section means.

Content principles

  • Verified, not hearsay. Techniques are grounded in primary sources - SAP Notes, official documentation, CVE/NVD records, and named public research - cited on each page.
  • Attack paired with defense. Every technique carries mitigation and detection guidance, so the Playbook is as useful to a defender as to a tester.
  • Kept current. SAP evolves; content is updated for current versions and hardening. If something looks dated, that’s a contribution waiting to happen.

Goals

  • To provide a comprehensive guide for conducting penetration tests on SAP environments.
  • To consolidate distributed, often outdated or hard-to-find knowledge into a structured and up-to-date guide.
  • To serve as a single, reliable point of reference for security professionals, pentesters, and researchers.
  • To foster collaboration and knowledge sharing within the security community.
  • To raise curiosity among security professionals in protecting SAP environments.

Contact Us

Anyone interested in supporting, contributing or giving feedback join us in our discord channel