Technology Overview
SAP NetWeaver Application Server for Java (AS Java), historically the “J2EE Engine,” is SAP’s Java EE-compliant application server platform. It runs standalone or alongside an ABAP stack in a “dual-stack” installation, and is the runtime for SAP NetWeaver Portal, Process Integration/Process Orchestration (PI/PO), Solution Manager Diagnostics, Visual Composer, and numerous Web Dynpro Java/JSP-based applications. Where the ABAP Platform’s security model is built around authorization objects, transaction codes, and the Security Audit Log, AS Java’s model is built around the User Management Engine (UME), servlet/EJB deployment descriptors, and a distinct set of administrative interfaces (NWA, ConfigTool, Visual Administrator, telnet console) - none of which map directly onto ABAP tooling, so a pentester moving from ABAP to Java targets should not assume familiar reconnaissance/exploitation patterns transfer unchanged.
An AS Java instance is built from the same dispatcher/server-process model as AS ABAP, but implemented on the JVM rather than the ABAP kernel:
- Java Dispatcher - accepts inbound connections (P4, HTTP(S), IIOP, Telnet) and routes each request to whichever Java server process currently has the least load. Unlike the ABAP dispatcher’s DIA/BTC/UPD work-process types, AS Java server processes are largely undifferentiated JVM instances.
- Server processes (
server0,server1, …) - each is a separate JVM (“cluster node”) hosting the deployed EAR/SDA/WAR applications; a single AS Java instance typically runs multiple server nodes for load distribution and isolation.server0is conventionally the first/primary node. - Central Services (SCS) - the Java-side equivalent of ABAP’s message server + enqueue server, providing cluster-wide messaging and lock coordination across dispatcher and server-process nodes. In a dual-stack system this is distinct from the ABAP-side ASCS.
- J2EE database - AS Java’s own configuration/persistence store (
SAP<SID>DBschema by convention), separate from any ABAP-side database schema even in a dual-stack install sharing one physical database. - User Management Engine (UME) - the central user/role/group store for all Java applications; can be backed by the local J2EE database, an external LDAP directory, or a connected AS ABAP system’s user base. All Java-side authorization (UME actions/roles, distinct from ABAP authorization objects) is enforced through the UME.
Administrative access to a running AS Java instance is exposed through several distinct client interfaces, each with its own protocol and port: web-based NWA (SAP NetWeaver Administrator) and /useradmin over HTTP(S); the Java-only ConfigTool (local OS-level access, bypasses the dispatcher entirely, talks directly to the database); the legacy Visual Administrator (deprecated since 7.1, replaced by NWA) over the P4 protocol; and the Telnet/Shell Administrator console.
AS Java’s default ports follow the same 5<instance-nr>XX numbering convention as ABAP’s 3<instance-nr>XX, using instance number NN (00–99). Throughout this playbook, ports are written as 5NN0x, resolving e.g. to 50004 for P4 on instance 00.
| Service | Default Port (instance 00) | Protocol | Notes |
|---|---|---|---|
| HTTP | 5NN00 (e.g. 50000) | HTTP | Portal, NWA, most web applications, /useradmin |
| HTTPS | 5NN01 (e.g. 50001) | HTTPS | Encrypted equivalent of the above; P4 can also be tunneled over this port |
| P4 | 5NN04 (e.g. 50004) | P4 (SAP’s RMI-based protocol) | Visual Administrator, remote deployment tooling, JMX-style management |
| P4 (SSL) | 5NN06 (e.g. 50006) | P4 over TLS | Encrypted P4 |
| Telnet / Shell Administrator | 5NN08 (e.g. 50008) | Telnet (unencrypted) | Administrative console (login, add <SERVICE>, lsc); SAP recommends deactivating if unused or restricting to a VPN tunnel |
| IIOP | 5NN02/5NN03 | IIOP / IIOP-SSL | RMI-IIOP for EJB/CORBA-style remote calls |
WarningThe P4 port (5NN04) is also the transport for AS Java’s RMI-based remote object protocol; a 2025 unauthenticated insecure-deserialization vulnerability in this protocol (CVE-2025-42944) makes P4 reachability from untrusted networks a critical finding on its own - see P4/RMI Insecure Deserialization.
AS Java releases track the same major version numbers as AS ABAP (both derive from the shared “SAP Basis”/“SAP NetWeaver AS” kernel lineage): 6.20/6.40 (early J2EE Engine, pre-NetWeaver naming), 7.00/7.01/7.02 (NetWeaver 2004s / NetWeaver 7.0 + enhancement packages), 7.10/7.11 (NetWeaver CE), 7.20, 7.30/7.31, 7.40, and 7.50 - the last major AS Java release, which remains the current on-premise target for security patching (e.g. CVE-2025-31324 and CVE-2025-42944 both affect SERVERCORE/VCFRAMEWORK release 7.50). Within each major release, SAP ships incremental fixes via Support Package Stacks (SPS); unlike ABAP’s SAP Notes/SNOTE workflow, most AS Java security fixes are delivered as a full SCA/SDA redeploy via the Software Update Manager (SUM) or JSPM rather than a note-level correction, which tends to make AS Java patch cycles slower in practice - a useful reconnaissance signal when comparing a target’s patch currency against note release dates.
