Reconnaissance
Reconnaissance against an SAP NetWeaver AS Java target centers on fingerprinting the J2EE Engine’s distinct port set (HTTP/HTTPS, P4, Telnet — see Technology Overview), enumerating deployed applications and their version/patch level, and identifying the UME’s user landscape (persistence store, default administrative accounts, role assignments). Unlike ABAP reconnaissance, there is no single dispatcher port to probe for a DIAG banner — AS Java exposes several independent administrative surfaces, each worth fingerprinting separately.
For any reference of tools or general SAP service-discovery methodology, see the SAP Attack Surface Discovery Project wiki.
