Home/Services/SAP & ERP Penetration Testing
security service

SAP & ERP Penetration Testing

SAP ERP penetration testing across NetWeaver, RFC and SAPRouter. We find default creds, SoD gaps and financial-fraud paths, fixed price with a full report.

Manual, expert-ledEvidence-based findingsFree remediation retest

SAP ERP penetration testing examines the platform that runs your finances, supply chain and payroll, where a single weakness can mean fraudulent payments, altered records or a full compromise of the system your business depends on. We test SAP and other major ERP platforms the way an attacker with a foothold would, then hand you a fix list your Basis and security teams can action.

What SAP and ERP penetration testing covers

ERP systems are where the money lives, yet they are often the least-tested part of the estate. They are complex, business-critical, and frequently guarded by the assumption that because they sit on an internal network, nobody can reach them. Attackers who phish a laptop or breach a VPN reach them easily, and once inside SAP the payoff is enormous: purchase orders, vendor bank details, salary data, the general ledger itself.

We assess the platform layer and the business layer together. That means the SAP NetWeaver technical stack, the RFC and gateway interfaces, SAPRouter, default and weak credentials, and privileged profiles like SAP_ALL, alongside the business-logic and authorization design that governs who can approve a payment or change a vendor’s bank account. For non-SAP estates we bring the same approach to Oracle E-Business Suite and Microsoft Dynamics.

SAP NetWeaver ABAP and Java stack testing, including known critical CVEs
RFC, message-server and SAP Gateway interface abuse checks
Default and standard-account credential testing, SAP* and DDIC included
Authorization and SAP_ALL misuse review, including privilege escalation paths
Segregation-of-duties gaps that enable financial fraud in the business process
Transport-system and change-management abuse, plus Oracle EBS and Dynamics testing

How we test an ERP platform

SAP is not a web app, and testing it well takes engineers who understand both offensive security and how the platform is actually built. We run a phased assessment tuned to the ERP world.

Discovery and fingerprinting

We map the landscape: application servers, the message server, SAPRouter, exposed dispatcher and gateway ports, the SAP versions and support-package levels in play, and any web-facing components such as Fiori or the Web Dispatcher. Version and patch state matter because SAP publishes monthly security notes, and unapplied notes are a reliable way in.

Authentication and default accounts

ERP systems ship with standard accounts, and installations that never changed them are common even in large companies. We check SAP* , DDIC, EARLYWATCH and their equivalents for default or weak passwords, test the RFC and gateway interfaces for unauthenticated access, and probe SAPRouter for permissive route rules that let an outsider reach systems that should be internal only.

Platform exploitation

Where the technical stack is vulnerable, we verify it. The RECON vulnerability in the NetWeaver Java stack, for example, allowed unauthenticated attackers to create an administrative user, and similar critical flaws surface regularly. We confirm real exposure carefully, on non-production systems where possible, so we never risk your live financial data.

Authorization and business-logic testing

This is where ERP testing earns its value. We examine the authorization design for over-broad profiles, unchecked privilege escalation to SAP_ALL, and, most importantly, segregation-of-duties failures. A user who can both create a vendor and approve a payment to that vendor can commit fraud without any technical exploit at all. We trace those paths through the real business process.

100%
manual, platform-aware testing by ERP-literate engineers
Safe
non-production first, no risk to live financial data
Free
retest after your Basis team remediates

Vulnerability classes we find in ERP systems

The findings that matter in an ERP engagement rarely look like a typical web bug. They are platform-specific, and they hit the business directly.

Default credentials and standard accounts

Standard SAP accounts with known default passwords remain one of the most frequent and highest-impact findings. A single unchanged SAP* or DDIC password can grant sweeping access, and these accounts are documented publicly, so an attacker does not need to guess.

Exposed RFC, gateway and SAPRouter

Interfaces built for system-to-system communication are often reachable by users who should never touch them. An open SAP Gateway or a permissive SAPRouter route can allow command execution or access to internal systems from outside the ERP boundary.

Segregation-of-duties and fraud paths

The classic ERP risk is a person holding two roles that should never be combined. Create-vendor plus approve-payment, or post-invoice plus release-payment, opens a direct route to fraudulent disbursement. We identify these SoD conflicts and show the concrete transaction sequence that would exploit them.

Missing SAP security notes

SAP releases patches through monthly security notes, and critical ones affecting NetWeaver, the Internet Communication Manager and other components appear regularly. Systems that lag behind on notes carry known, exploitable flaws. We identify which relevant notes are unapplied and rank them by real risk to your environment.

Insecure interfaces and integrations

ERP systems rarely stand alone. They exchange data with banks, tax portals, warehouses and middleware, and those integration points are frequently authenticated with static credentials or trusted by IP alone. We test the interfaces and the trust between systems, since a weak link in an integration can hand an attacker the same reach as a compromised ERP account.

Get a fixed quote

Want this tested on your own systems?

Free 20-minute scoping call, a fixed price with no hourly surprises, and a free retest once you fix what we find.

Get a fixed quote

What you get

The report speaks to the people who own ERP risk: leadership, Basis administrators, and the internal-audit or finance teams who care about fraud exposure.

Technical findings with reproduction

Each technical issue includes the impact, a CVSS score, the exact steps to reproduce it, and a specific remediation, whether that is applying a named SAP security note, resetting a standard account, or locking down a gateway ACL. Evidence accompanies every finding.

Business-risk and SoD findings

Segregation-of-duties conflicts are presented in business terms, with the transactions involved and the fraud scenario they enable, so your finance and audit teams understand not just that a gap exists but what it would cost. We recommend the role and authorization changes to close each one.

A prioritized remediation roadmap

ERP changes cannot all happen overnight, so we rank fixes by risk and effort, giving you a defensible order of work. A free retest after remediation confirms the highest-risk issues are genuinely resolved.

Compliance and standards mapping

ERP testing supports both security frameworks and the financial-controls obligations that ride on top of these systems.

ISO 27001 and financial controls

ISO 27001:2022 control A.8.2 covers privileged access rights and A.8.3 information access restriction, both central to ERP authorization design. Segregation-of-duties findings also feed the financial-reporting controls that internal and external auditors examine, since ERP is where those controls are enforced or bypassed.

GDPR, DORA and PCI DSS

ERP platforms hold employee and customer personal data, bringing GDPR article 32 into play for the technical measures protecting them. Financial entities running SAP under DORA can fold the results into ICT risk-management reporting. Where the ERP touches cardholder data, PCI DSS 4.0 requirement 11.4 penetration-testing obligations apply. We map every finding to the framework you name and provide an attestation letter.

Why manual ERP testing beats a generic scanner

General-purpose vulnerability scanners barely understand SAP. They do not speak RFC, they cannot reason about a segregation-of-duties conflict, and they will miss the authorization path that lets a warehouse clerk approve their own purchase order. ERP security demands engineers who know the platform: how NetWeaver is structured, what a dangerous transaction code looks like, and how a technical foothold turns into financial fraud. That expertise is the difference between a scan that reports open ports and an assessment that shows how someone could reroute a supplier payment into their own account.

Platforms and modules we cover

ERP is a family of very different products, and each carries its own risks. We tailor the assessment to what you actually run.

SAP ECC and S/4HANA

Whether you are on long-running ECC or have moved to S/4HANA, we test the NetWeaver foundation, the Fiori front end, and the HANA database layer beneath. A migration is a particularly good time to test, because roles are being rebuilt and authorization mistakes made during the project are easy to bake in permanently if nobody checks them.

Finance, procurement and HR modules

The modules that move money and hold personal data draw the most attacker interest. We focus authorization and segregation-of-duties testing on the finance, procurement and payroll processes, tracing who can create a vendor, approve an invoice, change bank details, or run payroll, and which combinations of those rights create a fraud path.

Oracle EBS and Microsoft Dynamics

For non-SAP estates we bring the same rigor to Oracle E-Business Suite and Microsoft Dynamics, covering their technical stacks, default and shared accounts, integration interfaces, and the authorization design that governs financial transactions. The platform changes, but the questions an attacker asks do not.

Pricing

ERP engagements are scoped to the size and complexity of the landscape: how many systems and clients, whether we test the technical platform, the business authorizations, or both, and whether it is SAP, Oracle EBS or Dynamics. These are complex platforms, so pricing sits at the higher end of application testing.

Engagement What’s included Timeline Price
Platform review Single SAP or ERP system, technical-stack testing, default-credential and interface checks, missing security notes, report 5–8 working days from €3,500
Platform plus authorization Technical testing combined with an authorization and SAP_ALL review and privilege-escalation paths 8–12 working days €6,000–€12,000
Full ERP assessment Multiple systems and clients, deep segregation-of-duties and fraud-path analysis, exec + technical + audit report 12–20 working days €8,000–€20,000+
Compliance add-on Mapping and attestation for ISO 27001, DORA, GDPR or PCI DSS requirements with any tier from €800
Custom / large estate Global ERP landscape, S/4HANA migration assurance or blended red-team objectives on scoping custom

Every engagement is fixed-price, quoted after a free 20-minute scoping call, and a retest is included. Get a fixed quote

FAQ

How much does SAP ERP penetration testing cost?
A single-system platform review starts from €3,500, while a full assessment across multiple systems with deep segregation-of-duties analysis ranges from €8,000 to €20,000 and up. You get a fixed quote after a free scoping call.
Will you test on our production ERP?
We test on non-production or a copy wherever possible, and we never run checks that risk your live financial data. Any activity against production is agreed in advance and kept to safe, read-oriented techniques.
Do you check for default SAP accounts like SAP* and DDIC?
Yes. Standard-account default passwords are among the most common and highest-impact findings, so we test SAP*, DDIC, EARLYWATCH and their equivalents, along with the RFC and gateway interfaces for unauthenticated access.
Can you find segregation-of-duties problems that enable fraud?
Yes, and it is a core part of the work. We trace authorization paths that let one person both create a vendor and approve a payment, or post and release an invoice, and we present the exact transaction sequence a fraudster would use.
Do you test Oracle E-Business Suite and Microsoft Dynamics too?
Yes. The same platform-aware approach applies to Oracle EBS and Microsoft Dynamics, covering their technical stacks, default accounts and authorization models alongside SAP.
Does this help with ISO 27001, DORA or financial-controls audits?
The report maps technical findings to ISO 27001 privileged-access controls and PCI DSS 11.4, and presents SoD conflicts in the business terms your financial-controls auditors need. Financial entities can fold the results into DORA ICT risk reporting.
How long does an ERP engagement take?
A single-system platform review runs five to eight working days, and a full multi-system assessment with fraud-path analysis takes twelve to twenty. Critical technical findings are reported to you as soon as we confirm them.
What will you deliver?
An executive summary, a technical report with each finding’s CVSS score, reproduction steps and named SAP security notes to apply, a business-risk view of segregation-of-duties gaps, and a prioritized remediation roadmap. A free retest confirms the fixes.

Related services

Who needs this

Enterprises across Europe running SAP, Oracle E-Business Suite or Microsoft Dynamics as the backbone of finance, procurement and payroll. It matters most before an S/4HANA migration, ahead of a financial-controls or ISO 27001 audit, or when internal audit has flagged segregation-of-duties concerns that need independent verification. Manufacturers, retailers and financial firms that run their core operations on ERP gain the most, because a single fraudulent transaction path can cost far more than the assessment.

why safetybis

Security you can prove

The same standard on every engagement, big or small.

Evidence, not opinions

Every finding ships with a reproduction and proof of concept — no vague "maybe vulnerable".

Humans over scanners

Certified engineers find the logic flaws and chained attacks automated tools walk straight past.

Fixed price, free retest

You know the cost up front, and verifying the fix is part of the deal — not a second invoice.

500+
assessments delivered
<30min
incident first response
12k+
infections removed
98%
fixed within one retest
$ safetybis quote --service "SAP & ERP Penetration Testing"

Ready to lock this down?

Free scoping call, fixed price, free retest. Tell us what you're running and we'll take it from there — usually within one business day.

get in touch

Tell us what you're running

Scoping is free. We reply within one business day, and under 30 minutes for active incidents.