-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathexample_report.html
More file actions
211 lines (211 loc) · 89.9 KB
/
Copy pathexample_report.html
File metadata and controls
211 lines (211 loc) · 89.9 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
<!doctype html>
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width,initial-scale=1">
<meta name="generator" content="SAPstract 2.2.0">
<title>SAPstract audit — prd-app-01.example.test</title>
<script>try{document.documentElement.dataset.theme=localStorage.getItem('sapstract-theme')||'light'}catch(e){document.documentElement.dataset.theme='light'}</script>
<style>
:root{color-scheme:light;--bg:#f3f4f6;--surface:#fff;--surface-alt:#f8fafc;--text:#1f2937;--muted:#64748b;--line:#cbd5e1;--line-strong:#94a3b8;--accent:#1d4ed8;--accent-soft:#dbeafe;--critical:#b91c1c;--critical-soft:#fee2e2;--high:#c2410c;--high-soft:#ffedd5;--medium:#a16207;--medium-soft:#fef3c7;--low:#1d4ed8;--low-soft:#dbeafe;--ok:#15803d;--ok-soft:#dcfce7}
html[data-theme="dark"]{color-scheme:dark;--bg:#161616;--surface:#222;--surface-alt:#2b2b2b;--text:#ededed;--muted:#b8b8b8;--line:#484848;--line-strong:#686868;--accent:#e5e5e5;--accent-soft:#363636;--critical:#fca5a5;--critical-soft:#4c1d24;--high:#fdba74;--high-soft:#4a2918;--medium:#fde68a;--medium-soft:#473b16;--low:#d4d4d4;--low-soft:#333;--ok:#86efac;--ok-soft:#163b28}
*{box-sizing:border-box}html{scroll-behavior:smooth}body{margin:0;background:var(--bg);color:var(--text);font:14px/1.5 Arial,Helvetica,sans-serif}a{color:var(--accent)}code{font-family:ui-monospace,SFMono-Regular,Consolas,monospace}.wrap{max-width:1500px;margin:auto;padding:24px}.hero{display:flex;justify-content:space-between;gap:24px;align-items:flex-start;padding:24px;border:1px solid var(--line);border-top:5px solid var(--accent);background:var(--surface)}.brand{font-size:12px;letter-spacing:.12em;text-transform:uppercase;color:var(--accent);font-weight:700}.hero h1{font-size:clamp(28px,4vw,44px);line-height:1.1;margin:.2em 0}.hero-actions{display:flex;flex-direction:column;align-items:flex-end;gap:10px;min-width:180px}.overall-index{padding:10px 12px;border:1px solid var(--line);background:var(--surface-alt);text-align:right}.overall-index strong{font-size:22px}.muted{color:var(--muted)}button,.filter{font:inherit;color:var(--text);background:var(--surface);border:1px solid var(--line-strong);padding:8px 11px;border-radius:3px}.theme-toggle{cursor:pointer;white-space:nowrap}.theme-toggle:hover{border-color:var(--accent)}
nav{position:sticky;top:0;z-index:4;margin:14px 0;display:flex;overflow-x:auto;background:var(--surface);border:1px solid var(--line)}nav a{text-decoration:none;color:var(--text);white-space:nowrap;padding:9px 12px;border-right:1px solid var(--line)}nav a:hover{background:var(--accent-soft);color:var(--accent)}section,.report-section{display:block;margin:14px 0;border:1px solid var(--line);background:var(--surface)}section{padding:18px}.report-section>summary{display:flex;justify-content:space-between;gap:16px;align-items:center;padding:15px 18px;cursor:pointer;list-style-position:inside;background:var(--surface-alt)}.report-section[open]>summary{border-bottom:1px solid var(--line)}.report-section>summary h2{display:inline;margin:0}.section-body{padding:18px}.section-head{display:flex;justify-content:space-between;gap:16px;align-items:end;margin-bottom:12px}h2{margin:0 0 4px;font-size:22px}h3{margin:0;font-size:16px}.filter{min-width:270px}.pill,.count-badge{display:inline-block;padding:3px 8px;border:1px solid var(--line);background:var(--surface-alt);white-space:nowrap}
.score-grid{display:grid;grid-template-columns:repeat(auto-fit,minmax(220px,1fr));gap:10px;margin:14px 0}.score-card{border:1px solid var(--line);border-top:4px solid var(--line-strong);padding:14px;background:var(--surface)}.score-card-head{display:flex;justify-content:space-between;gap:8px;align-items:start}.score-card h3{font-size:15px}.grade{display:grid;place-items:center;width:30px;height:30px;border:1px solid currentColor;font-weight:700}.score-value{display:flex;align-items:baseline;gap:4px;margin-top:8px}.score-value strong{font-size:30px}.score-value span,.score-card p,.score-card small{color:var(--muted)}.score-card p{margin:6px 0}.score-meter{height:7px;background:var(--surface-alt);border:1px solid var(--line)}.score-meter span{display:block;height:100%;background:currentColor}.score-a{color:var(--ok);border-top-color:var(--ok)}.score-b{color:var(--low);border-top-color:var(--low)}.score-c{color:var(--medium);border-top-color:var(--medium)}.score-d{color:var(--high);border-top-color:var(--high)}.score-f{color:var(--critical);border-top-color:var(--critical)}.score-card h3,.score-card .score-value strong{color:var(--text)}
.score-card{text-decoration:none;display:block}.score-card:hover{background:var(--surface-alt);border-color:currentColor}.topology-graph{display:grid;grid-template-columns:minmax(210px,1fr) auto minmax(190px,.7fr) auto minmax(210px,1fr);gap:12px;align-items:center;padding:16px;border:1px solid var(--line);background:var(--surface-alt)}.graph-lane{display:grid;gap:8px;align-content:center}.graph-lane h3{text-align:center;color:var(--muted);font-size:13px}.graph-node,.graph-host{padding:10px;border:1px solid var(--line-strong);background:var(--surface);display:grid;gap:3px}.graph-node strong,.graph-host strong{overflow-wrap:anywhere}.graph-node small,.graph-host small{color:var(--muted)}.graph-host{border:3px solid var(--accent);text-align:center;padding:18px}.graph-host span,.node-scope{text-transform:uppercase;font-size:11px;letter-spacing:.06em;color:var(--muted)}.graph-connector{display:grid;gap:4px;text-align:center;color:var(--muted)}.graph-connector b{font-size:25px;color:var(--accent)}.database-node{border-left:5px solid var(--medium)}.remote-peer-node{border-left:5px solid var(--accent)}.posture-card{border:1px solid var(--line);border-left:5px solid var(--medium);padding:12px;background:var(--surface-alt);margin:12px 0}.status-badge{display:inline-block;padding:2px 7px;border:1px solid var(--line-strong);background:var(--surface-alt);font-weight:700}.status-observed,.status-enabled,.status-listening,.status-configured,.status-local-observed,.status-remote-observed,.status-mixed{color:var(--ok);background:var(--ok-soft)}.status-possible,.status-undetermined{color:var(--medium);background:var(--medium-soft)}.status-not-observed{color:var(--muted)}
.risk{display:grid;grid-template-columns:repeat(4,1fr);gap:8px}.risk div{padding:12px;border:1px solid currentColor;background:var(--surface-alt)}.risk b{font-size:22px;display:block}.critical{color:var(--critical)}.high{color:var(--high)}.medium{color:var(--medium)}.low{color:var(--low)}.cards{display:grid;grid-template-columns:repeat(auto-fit,minmax(140px,1fr));gap:8px;margin:12px 0}.card{padding:12px;border:1px solid var(--line);background:var(--surface-alt)}.card b{font-size:22px;display:block}.card small{color:var(--muted)}.notice{padding:11px 13px;border-left:4px solid var(--accent);background:var(--accent-soft)}
.technical-group,.finding-group,.finding{margin-top:10px;border:1px solid var(--line);background:var(--surface)}.technical-group>summary,.finding-group>summary{display:flex;justify-content:space-between;gap:12px;padding:11px 13px;cursor:pointer;background:var(--surface-alt);font-weight:700}.technical-group[open]>summary,.finding-group[open]>summary{border-bottom:1px solid var(--line)}.technical-group-body,.finding-list{padding:12px}.summary-meta{color:var(--muted);font-weight:400}.finding{border-left:5px solid var(--line-strong)}.finding>summary{display:grid;grid-template-columns:auto auto minmax(220px,1fr) auto;gap:9px;align-items:center;padding:10px;cursor:pointer}.finding-title{font-weight:700}.finding-summary-meta{color:var(--muted);text-align:right}.severity-critical{border-left-color:var(--critical)}.severity-high{border-left-color:var(--high)}.severity-medium{border-left-color:var(--medium)}.severity-low{border-left-color:var(--low)}.severity-badge{padding:2px 7px;border:1px solid currentColor;font-size:12px;font-weight:700}.severity-critical .severity-badge{color:var(--critical);background:var(--critical-soft)}.severity-high .severity-badge{color:var(--high);background:var(--high-soft)}.severity-medium .severity-badge{color:var(--medium);background:var(--medium-soft)}.severity-low .severity-badge{color:var(--low);background:var(--low-soft)}.finding-body{padding:0 12px 12px}.finding-body dl{margin:0;display:grid;gap:8px}.finding-body dl>div{display:grid;grid-template-columns:150px 1fr;border-top:1px solid var(--line);padding-top:8px}.finding-body dt{font-weight:700}.finding-body dd{margin:0;overflow-wrap:anywhere}
.scroll-hint{display:flex;justify-content:flex-end;color:var(--muted);font-size:12px;margin:4px 0}.table-wrap{width:100%;max-width:100%;overflow-x:auto;overflow-y:visible;border:1px solid var(--line);scrollbar-gutter:stable}.table-wrap::-webkit-scrollbar{height:12px}.table-wrap::-webkit-scrollbar-track{background:var(--surface-alt)}.table-wrap::-webkit-scrollbar-thumb{background:var(--line-strong);border:2px solid var(--surface-alt)}table{border-collapse:collapse;width:max-content;min-width:100%}th,td{text-align:left;vertical-align:top;padding:9px 11px;border-bottom:1px solid var(--line);min-width:110px;max-width:430px;overflow-wrap:anywhere}th{position:sticky;top:0;background:var(--surface-alt);font-size:12px;text-transform:uppercase;letter-spacing:.04em}tbody tr:hover td{background:var(--accent-soft)}.empty{padding:18px;color:var(--muted)}footer{text-align:center;color:var(--muted);padding:26px}.hide{display:none!important}
@media(max-width:900px){.topology-graph{grid-template-columns:1fr}.graph-connector b{transform:rotate(90deg)}.graph-connector span{display:none}}@media(max-width:760px){.wrap{padding:10px}.hero{flex-direction:column}.hero-actions{align-items:stretch;width:100%}.overall-index{text-align:left}.risk{grid-template-columns:1fr 1fr}.section-head{align-items:stretch;flex-direction:column}.filter{min-width:0;width:100%}.finding>summary{grid-template-columns:auto auto 1fr}.finding-summary-meta{grid-column:1/-1;text-align:left}.finding-body dl>div{grid-template-columns:1fr}.summary-meta{display:none}}
@media print{:root,html[data-theme="dark"]{color-scheme:light;--bg:#fff;--surface:#fff;--surface-alt:#f4f4f4;--text:#111;--muted:#555;--line:#aaa;--line-strong:#777;--accent:#174ea6}body{background:#fff}.wrap{max-width:none;padding:0}.theme-toggle,nav,.filter,.scroll-hint{display:none}.report-section{break-inside:avoid}.table-wrap{overflow:visible}table{width:100%;min-width:0;font-size:9px}th,td{min-width:0;max-width:none;padding:4px}.finding-group,.finding{break-inside:avoid}}
</style>
</head>
<body><div class="wrap">
<header class="hero">
<div><div class="brand">SAPstract · Host posture</div><h1>prd-app-01.example.test</h1>
<p class="muted">Generated 2026-08-10T05:47:14Z · Schema sapstract-audit/v2 · Audit root /tmp/sapstract-example-fixture</p>
<p class="notice"><strong>Report context:</strong> Synthetic showcase only — no production data or credentials.</p>
<p>Review the section scores below to see where risk is concentrated. Scores reflect observed local evidence, not proof of exploitability or an SAP application-layer certification.</p>
</div>
<div class="hero-actions"><button class="theme-toggle" id="theme-toggle" type="button" aria-label="Switch color theme">Dark theme</button><div class="overall-index"><span class="muted">Aggregate index</span><br><strong>100/100 · F</strong><br><small>Critical remediation priority</small></div></div>
</header>
<nav><a href="#summary">Summary</a><a href="#topology">Topology</a><a href="#capabilities">Capabilities</a><a href="#database">Database</a><a href="#service-catalog">Service catalog</a><a href="#findings">Findings</a><a href="#systems">Systems</a><a href="#runtime">Runtime</a><a href="#sockets">Connections</a><a href="#ssfs">SSFS</a><a href="#profiles">Profiles</a><a href="#paths">Files</a><a href="#assessment">Assessment</a><a href="#coverage">Coverage</a></nav>
<section id="summary"><div class="section-head"><div><h2>Executive summary</h2><div class="muted">Passive evidence collected from this host</div></div><span class="pill">28 findings</span></div>
<h3>Risk by section</h3><div class="score-grid"><a class="score-card score-d" href="#findings-network"><div class="score-card-head"><h3>Network & exposed services</h3><span class="grade">D</span></div><div class="score-value"><strong>58</strong><span>/ 100</span></div><div class="score-meter" aria-label="58 out of 100"><span style="width:58%"></span></div><p>High observed risk</p><small>6 finding(s) · 0 critical · 1 high · 5 medium · 0 low</small></a>
<a class="score-card score-f" href="#findings-configuration"><div class="score-card-head"><h3>Configuration & access controls</h3><span class="grade">F</span></div><div class="score-value"><strong>100</strong><span>/ 100</span></div><div class="score-meter" aria-label="100 out of 100"><span style="width:100%"></span></div><p>Critical remediation priority</p><small>14 finding(s) · 0 critical · 9 high · 5 medium · 0 low</small></a>
<a class="score-card score-b" href="#findings-filesystem"><div class="score-card-head"><h3>Files & executable integrity</h3><span class="grade">B</span></div><div class="score-value"><strong>18</strong><span>/ 100</span></div><div class="score-meter" aria-label="18 out of 100"><span style="width:18%"></span></div><p>Limited hardening gaps</p><small>1 finding(s) · 0 critical · 1 high · 0 medium · 0 low</small></a>
<a class="score-card score-f" href="#findings-secrets"><div class="score-card-head"><h3>SSFS, credentials & client data</h3><span class="grade">F</span></div><div class="score-value"><strong>86</strong><span>/ 100</span></div><div class="score-meter" aria-label="86 out of 100"><span style="width:86%"></span></div><p>Critical remediation priority</p><small>4 finding(s) · 2 critical · 1 high · 1 medium · 0 low</small></a>
<a class="score-card score-c" href="#findings-operations"><div class="score-card-head"><h3>Operations, logging & command execution</h3><span class="grade">C</span></div><div class="score-value"><strong>34</strong><span>/ 100</span></div><div class="score-meter" aria-label="34 out of 100"><span style="width:34%"></span></div><p>Material hardening gaps</p><small>3 finding(s) · 0 critical · 1 high · 2 medium · 0 low</small></a></div>
<div class="risk"><div><b class="critical">2</b>Critical</div><div><b class="high">13</b>High</div><div><b class="medium">13</b>Medium</div><div><b class="low">0</b>Low</div></div>
<div class="cards"><div class="card"><b>1</b><small>SAP systems</small></div><div class="card"><b>10</b><small>service evidence rows</small></div><div class="card"><b>4</b><small>listening endpoints</small></div><div class="card"><b>1</b><small>observed connections</small></div><div class="card"><b>12</b><small>capability checks</small></div><div class="card"><b>1</b><small>database evidence rows</small></div><div class="card"><b>2</b><small>SSFS artifacts</small></div><div class="card"><b>0</b><small>SAP tools</small></div></div>
<div class="posture-card"><strong>Database placement: undetermined</strong><br><span>No database placement evidence was observed in the collected process, socket, path, or profile data.</span> <small>Confidence: low</small></div>
<p class="notice">SAPstract is deliberately read-only: it does not scan another host, call SAP web methods, log in, brute-force, decrypt SSFS, or print secrets. Validate high-impact changes with the responsible SAP Basis, security, database, and infrastructure owners.</p>
</section>
<details id="topology" class="report-section" open><summary><h2>SAP service and connection topology</h2><span class="count-badge">7 relationship(s)</span></summary><div class="section-body"><p class="notice">This graph shows observed local processes, services, listeners, and connections. “Remote” means the peer address was not loopback or another collected local socket address; confirm routing and database ownership before relying on the placement.</p><div class="topology-graph" role="img" aria-label="Observed SAP services connect through the audited host to database and remote peers"><div class="graph-lane"><h3>Enabled and observed service groups</h3><div class="graph-node service-node"><strong>ABAP core services</strong><small>2 evidence record(s); 1 listener(s)</small></div><div class="graph-node service-node"><strong>Boundary & cloud connectors</strong><small>2 evidence record(s); 1 listener(s)</small></div><div class="graph-node service-node"><strong>Other SAP services</strong><small>1 evidence record(s); 0 listener(s)</small></div><div class="graph-node service-node"><strong>Management services</strong><small>2 evidence record(s); 1 listener(s)</small></div><div class="graph-node service-node"><strong>Integration services</strong><small>3 evidence record(s); 1 listener(s)</small></div></div><div class="graph-connector"><span>runs / listens</span><b>→</b></div><div class="graph-host"><span>SAP host</span><strong>prd-app-01.example.test</strong><small>1 system(s) · 5 socket(s)</small></div><div class="graph-connector"><span>connects to</span><b>→</b></div><div class="graph-lane"><h3>Database and remote peers</h3><div class="graph-node remote-peer-node"><strong>10.20.40.25:49152</strong><span class="node-scope">remote</span><small>Peer observed from gwrd</small></div><div class="graph-node database-node"><strong>Unknown</strong><span class="node-scope">undetermined</span><small>not observed — Active database placement requires authenticated or runtime follow-up.</small></div></div></div><details class="technical-group"><summary><span>Topology relationships and evidence</span><span class="summary-meta">7 edge(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table id="topology-edges-table"><thead><tr><th>Source</th><th>Target</th><th>Relationship</th><th>State</th><th>Confidence</th><th>Evidence</th></tr></thead><tbody><tr class="search-row"><td>host</td><td>remote-10-20-40-25-49152</td><td>observed SAP connection</td><td>ESTAB</td><td>high</td><td>gwrd ESTAB: 10.20.30.10:3300 → 10.20.40.25:49152</td></tr>
<tr class="search-row"><td>host</td><td>service-abap-core-services</td><td>runs or exposes</td><td>observed</td><td>high</td><td>2 process/service/socket record(s)</td></tr>
<tr class="search-row"><td>host</td><td>service-boundary-cloud-connectors</td><td>runs or exposes</td><td>observed</td><td>high</td><td>2 process/service/socket record(s)</td></tr>
<tr class="search-row"><td>host</td><td>service-other-sap-services</td><td>runs or exposes</td><td>observed</td><td>high</td><td>1 process/service/socket record(s)</td></tr>
<tr class="search-row"><td>host</td><td>service-management-services</td><td>runs or exposes</td><td>observed</td><td>high</td><td>2 process/service/socket record(s)</td></tr>
<tr class="search-row"><td>host</td><td>service-integration-services</td><td>runs or exposes</td><td>observed</td><td>high</td><td>3 process/service/socket record(s)</td></tr>
<tr class="search-row"><td>host</td><td>db-undetermined</td><td>database placement undetermined</td><td>undetermined</td><td>low</td><td>Active database placement requires authenticated or runtime follow-up.</td></tr></tbody></table></div></div></details></div></details>
<details id="capabilities" class="report-section" open><summary><h2>SAP capabilities and enabled surfaces</h2><span class="count-badge">12 check(s)</span></summary><div class="section-body"><p class="muted">Observed means local evidence exists. Not observed is never equivalent to disabled. WebGUI host artifacts are marked enabled with medium confidence and still require SICF confirmation.</p><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table id="capabilities-table"><thead><tr><th>Category</th><th>Capability</th><th>Status</th><th>Confidence</th><th>Evidence</th><th>Required validation</th></tr></thead><tbody><tr class="search-row"><td>Application stack</td><td>ABAP application server</td><td><span class="status-badge status-observed">Observed</span></td><td>high</td><td>NetWeaver system, dispatcher process, or DIAG listener observed.</td><td>Confirm active instances and roles with SAPControl and authenticated SAP administration.</td></tr><tr class="search-row"><td>Web & UI</td><td>SAP WebGUI for ABAP</td><td><span class="status-badge status-not-observed">Not observed</span></td><td>low</td><td>No WebGUI-named host artifact was observed; this is not proof that the database-backed ICF service is disabled.</td><td>Confirm /sap/bc/gui/sap/its/webgui status in SICF.</td></tr><tr class="search-row"><td>Web & UI</td><td>SAP HTTP(S) application surface</td><td><span class="status-badge status-not-observed">Not observed</span></td><td>medium</td><td>No recognized application HTTP(S) listener was recorded.</td><td>A clean host result is not proof of firewall or proxy absence.</td></tr><tr class="search-row"><td>Integration</td><td>RFC Gateway</td><td><span class="status-badge status-listening">Listening</span></td><td>high</td><td>RFC Gateway listener observed.</td><td>Validate effective secinfo/reginfo/prxyinfo and SNC with authorized SAP tooling.</td></tr><tr class="search-row"><td>Transport security</td><td>Secure Network Communications (SNC)</td><td><span class="status-badge status-configured">Configured</span></td><td>medium</td><td>One or more snc/* profile parameters were observed.</td><td>Validate effective runtime values and negotiated QoP per connection; configuration presence is not proof of enforcement.</td></tr><tr class="search-row"><td>Application stack</td><td>SAP NetWeaver Java</td><td><span class="status-badge status-not-observed">Not observed</span></td><td>medium</td><td>No matching local runtime evidence was collected.</td><td>Confirm collection coverage before treating this as disabled.</td></tr><tr class="search-row"><td>Boundary & cloud</td><td>SAP Cloud Connector</td><td><span class="status-badge status-not-observed">Not observed</span></td><td>medium</td><td>No matching local runtime evidence was collected.</td><td>Confirm collection coverage before treating this as disabled.</td></tr><tr class="search-row"><td>Boundary & cloud</td><td>SAProuter</td><td><span class="status-badge status-observed">Observed</span></td><td>high</td><td>Matching service, process, or socket evidence was collected.</td><td>Review the corresponding technical evidence and validate effective configuration.</td></tr><tr class="search-row"><td>Boundary & cloud</td><td>SAP Web Dispatcher</td><td><span class="status-badge status-not-observed">Not observed</span></td><td>medium</td><td>No matching local runtime evidence was collected.</td><td>Confirm collection coverage before treating this as disabled.</td></tr><tr class="search-row"><td>Web & UI</td><td>Internet Graphics Server (IGS)</td><td><span class="status-badge status-not-observed">Not observed</span></td><td>medium</td><td>No matching local runtime evidence was collected.</td><td>Confirm collection coverage before treating this as disabled.</td></tr><tr class="search-row"><td>Management</td><td>SAP Host Agent / Start Service</td><td><span class="status-badge status-observed">Observed</span></td><td>high</td><td>Matching service, process, or socket evidence was collected.</td><td>Review the corresponding technical evidence and validate effective configuration.</td></tr><tr class="search-row"><td>Data tier</td><td>Database placement</td><td><span class="status-badge status-undetermined">undetermined</span></td><td>low</td><td>No database placement evidence was observed in the collected process, socket, path, or profile data.</td><td>Validate the inferred engine and placement with SAP profiles, SAPControl, and the database owner before changing connectivity.</td></tr></tbody></table></div></div></details>
<details id="database" class="report-section" open><summary><h2>Database landscape</h2><span class="count-badge">undetermined · 1 evidence row(s)</span></summary><div class="section-body"><div class="posture-card"><strong>No database placement evidence was observed in the collected process, socket, path, or profile data.</strong><br><small>Confidence: low. A non-loopback peer can still be another address on the same host if socket coverage is incomplete.</small></div><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table id="database-table"><thead><tr><th>Engine</th><th>Placement</th><th>Endpoint/artifact</th><th>State</th><th>Confidence</th><th>Evidence</th></tr></thead><tbody><tr class="search-row"><td>Unknown</td><td>undetermined</td><td>not observed</td><td>undetermined</td><td>low</td><td>Active database placement requires authenticated or runtime follow-up.</td></tr></tbody></table></div></div></details>
<details id="service-catalog" class="report-section" open><summary><h2>Categorized SAP service catalog</h2><span class="count-badge">10 evidence row(s)</span></summary><div class="section-body"><div class="section-head"><div class="muted">Processes, service-manager entries, listeners, and established connections grouped by technical purpose</div><input class="filter" placeholder="Filter service evidence…" data-target="service-catalog-groups"></div><div id="service-catalog-groups"><details class="technical-group service-category"><summary><span>ABAP core services</span><span class="summary-meta">2 evidence record(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table><thead><tr><th>Component</th><th>Status</th><th>Endpoint</th><th>Scope</th><th>Transport</th><th>Process/account</th><th>Source</th></tr></thead><tbody><tr class="search-row"><td>SAP Dispatcher / SAP DIAG or Enqueue</td><td>LISTEN</td><td>0.0.0.0:3200</td><td>all-interfaces</td><td>NI/DIAG</td><td>disp+work</td><td>socket</td></tr><tr class="search-row"><td>SAP Dispatcher/Work Process</td><td>running</td><td>not attributed</td><td>local</td><td>process</td><td>disp+work (PID 200)</td><td>process</td></tr></tbody></table></div></div></details><details class="technical-group service-category"><summary><span>Boundary & cloud connectors</span><span class="summary-meta">2 evidence record(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table><thead><tr><th>Component</th><th>Status</th><th>Endpoint</th><th>Scope</th><th>Transport</th><th>Process/account</th><th>Source</th></tr></thead><tbody><tr class="search-row"><td>SAProuter</td><td>LISTEN</td><td>0.0.0.0:3299</td><td>all-interfaces</td><td>NI/Router</td><td>saprouter</td><td>socket</td></tr><tr class="search-row"><td>SAProuter</td><td>running</td><td>not attributed</td><td>local</td><td>process</td><td>saprouter (PID 300)</td><td>process</td></tr></tbody></table></div></div></details><details class="technical-group service-category"><summary><span>Integration services</span><span class="summary-meta">3 evidence record(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table><thead><tr><th>Component</th><th>Status</th><th>Endpoint</th><th>Scope</th><th>Transport</th><th>Process/account</th><th>Source</th></tr></thead><tbody><tr class="search-row"><td>SAP RFC Gateway</td><td>LISTEN</td><td>0.0.0.0:3300</td><td>all-interfaces</td><td>RFC/NI (typically unencrypted)</td><td>gwrd</td><td>socket</td></tr><tr class="search-row"><td>SAP RFC Gateway</td><td>ESTAB</td><td>10.20.30.10:3300 → 10.20.40.25:49152</td><td>connected</td><td>RFC/NI (typically unencrypted)</td><td>gwrd</td><td>socket</td></tr><tr class="search-row"><td>SAP RFC Gateway</td><td>running</td><td>not attributed</td><td>local</td><td>process</td><td>gwrd (PID 201)</td><td>process</td></tr></tbody></table></div></div></details><details class="technical-group service-category"><summary><span>Management services</span><span class="summary-meta">2 evidence record(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table><thead><tr><th>Component</th><th>Status</th><th>Endpoint</th><th>Scope</th><th>Transport</th><th>Process/account</th><th>Source</th></tr></thead><tbody><tr class="search-row"><td>SAP Start Service HTTP</td><td>LISTEN</td><td>0.0.0.0:50013</td><td>all-interfaces</td><td>HTTP/SOAP</td><td>sapstartsrv</td><td>socket</td></tr><tr class="search-row"><td>SAP Start Service</td><td>running</td><td>not attributed</td><td>local</td><td>process</td><td>sapstartsrv (PID 202)</td><td>process</td></tr></tbody></table></div></div></details><details class="technical-group service-category"><summary><span>Other SAP services</span><span class="summary-meta">1 evidence record(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table><thead><tr><th>Component</th><th>Status</th><th>Endpoint</th><th>Scope</th><th>Transport</th><th>Process/account</th><th>Source</th></tr></thead><tbody><tr class="search-row"><td>SAP component</td><td>active/running</td><td>not attributed</td><td>local</td><td>service manager</td><td></td><td>service</td></tr></tbody></table></div></div></details></div></div></details>
<section id="findings"><div class="section-head"><div><h2>Prioritized findings by risk section</h2><div class="muted">Each risk domain has its own report section and filter below.</div></div><span class="pill">28 total finding(s)</span></div></section>
<details id="findings-network" class="report-section finding-section"><summary><h2>Network & exposed services findings</h2><span class="count-badge">6 finding(s) · 58/100 · grade D</span></summary><div class="section-body"><div class="section-head"><div><strong>High observed risk</strong><div class="muted">0 critical · 1 high · 5 medium · 0 low</div></div><input class="filter" placeholder="Filter Network & exposed services findings…" data-target="finding-list-network"></div><div class="finding-list" id="finding-list-network">
<details class="finding search-item severity-medium"><summary><span class="severity-badge">Medium</span><code>DIAG-001</code><span class="finding-title">SAP Dispatcher/DIAG endpoint requires SNC and boundary validation</span><span class="finding-summary-meta">0.0.0.0:3200 · +8</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>0.0.0.0:3200</dd></div><div><dt>Evidence and impact</dt><dd>The 32NN endpoint is listening beyond loopback; classic DIAG does not provide confidentiality unless SNC is negotiated.</dd></div><div><dt>Recommended change</dt><dd>Restrict network paths to approved clients, require SNC with privacy where feasible, and validate enforcement from an authorized client.</dd></div><div><dt>Reference</dt><dd>OWASP SAP Pentest Playbook: Dispatcher; OWASP sncscan</dd></div></dl></div></details>
<details class="finding search-item severity-medium"><summary><span class="severity-badge">Medium</span><code>NET-006</code><span class="finding-title">SAP administration endpoint is network-reachable</span><span class="finding-summary-meta">SAP RFC Gateway at 0.0.0.0:3300 · +8</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>SAP RFC Gateway at 0.0.0.0:3300</dd></div><div><dt>Evidence and impact</dt><dd>An SAP administrative service is listening beyond loopback. Encryption alone does not provide network isolation or strong administrative authorization.</dd></div><div><dt>Recommended change</dt><dd>Restrict the listener and firewall path to approved administration networks, require strong authentication, and review TLS certificate trust and patch level.</dd></div><div><dt>Reference</dt><dd>SAP component security guidance; OWASP CBAS attack-surface research</dd></div></dl></div></details>
<details class="finding search-item severity-medium"><summary><span class="severity-badge">Medium</span><code>GW-001</code><span class="finding-title">Unencrypted RFC Gateway endpoint is reachable</span><span class="finding-summary-meta">0.0.0.0:3300 · +8</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>0.0.0.0:3300</dd></div><div><dt>Evidence and impact</dt><dd>Port family 33NN is normally RFC/NI without SNC. This does not prove that individual RFC sessions lack application controls.</dd></div><div><dt>Recommended change</dt><dd>Use SNC for sensitive RFC paths, restrict gateway reachability, and enforce restrictive secinfo/reginfo rules.</dd></div><div><dt>Reference</dt><dd>OWASP SAP Pentest Playbook: RFC Gateway</dd></div></dl></div></details>
<details class="finding search-item severity-high"><summary><span class="severity-badge">High</span><code>NET-003</code><span class="finding-title">Cleartext SAP management endpoint is network-reachable</span><span class="finding-summary-meta">SAP Start Service HTTP at 0.0.0.0:50013 · +18</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>SAP Start Service HTTP at 0.0.0.0:50013</dd></div><div><dt>Evidence and impact</dt><dd>The HTTP/administration endpoint is listening on 0.0.0.0 without transport encryption.</dd></div><div><dt>Recommended change</dt><dd>Prefer the TLS endpoint, bind cleartext management to loopback when SAP requires it locally, and restrict remote access with host/network controls.</dd></div><div><dt>Reference</dt><dd>SAP Host Agent and SAP Start Service security guidance</dd></div></dl></div></details>
<details class="finding search-item severity-medium"><summary><span class="severity-badge">Medium</span><code>NET-005</code><span class="finding-title">SAProuter is network-reachable</span><span class="finding-summary-meta">SAProuter at 0.0.0.0:3299 · +8</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>SAProuter at 0.0.0.0:3299</dd></div><div><dt>Evidence and impact</dt><dd>SAProuter is expected to be a boundary component, but its reachability makes route-table scope and patching security-critical.</dd></div><div><dt>Recommended change</dt><dd>Review saprouttab for least-privilege routes, require SNC where appropriate, restrict management access, and keep SAProuter patched.</dd></div><div><dt>Reference</dt><dd>OWASP SAP Pentest Playbook: SAProuter</dd></div></dl></div></details>
<details class="finding search-item severity-medium"><summary><span class="severity-badge">Medium</span><code>GW-001</code><span class="finding-title">Unencrypted RFC Gateway endpoint is reachable</span><span class="finding-summary-meta">10.20.30.10:3300 · +8</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>10.20.30.10:3300</dd></div><div><dt>Evidence and impact</dt><dd>Port family 33NN is normally RFC/NI without SNC. This does not prove that individual RFC sessions lack application controls.</dd></div><div><dt>Recommended change</dt><dd>Use SNC for sensitive RFC paths, restrict gateway reachability, and enforce restrictive secinfo/reginfo rules.</dd></div><div><dt>Reference</dt><dd>OWASP SAP Pentest Playbook: RFC Gateway</dd></div></dl></div></details>
</div></div></details>
<details id="findings-configuration" class="report-section finding-section"><summary><h2>Configuration & access controls findings</h2><span class="count-badge">14 finding(s) · 100/100 · grade F</span></summary><div class="section-body"><div class="section-head"><div><strong>Critical remediation priority</strong><div class="muted">0 critical · 9 high · 5 medium · 0 low</div></div><input class="filter" placeholder="Filter Configuration & access controls findings…" data-target="finding-list-configuration"></div><div class="finding-list" id="finding-list-configuration">
<details class="finding search-item severity-high"><summary><span class="severity-badge">High</span><code>ACL-001</code><span class="finding-title">SAP access-control file contains a broad wildcard rule</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/global/security/data/reginfo · +18</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/global/security/data/reginfo</dd></div><div><dt>Evidence and impact</dt><dd>A permissive wildcard pattern was detected in reginfo, including positional SAProuter target-host wildcards; rule contents were not copied into the report.</dd></div><div><dt>Recommended change</dt><dd>Review rules in order, replace broad permits with explicit program/user/host or route entries, test in logging/simulation mode where supported, and reload safely.</dd></div><div><dt>Reference</dt><dd>SAP RFC Gateway guidance; SAP Note 1895350; SEC Consult CVE-2022-27668</dd></div></dl></div></details>
<details class="finding search-item severity-high"><summary><span class="severity-badge">High</span><code>ACL-001</code><span class="finding-title">SAP access-control file contains a broad wildcard rule</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/global/security/data/secinfo · +18</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/global/security/data/secinfo</dd></div><div><dt>Evidence and impact</dt><dd>A permissive wildcard pattern was detected in secinfo, including positional SAProuter target-host wildcards; rule contents were not copied into the report.</dd></div><div><dt>Recommended change</dt><dd>Review rules in order, replace broad permits with explicit program/user/host or route entries, test in logging/simulation mode where supported, and reload safely.</dd></div><div><dt>Reference</dt><dd>SAP RFC Gateway guidance; SAP Note 1895350; SEC Consult CVE-2022-27668</dd></div></dl></div></details>
<details class="finding search-item severity-medium"><summary><span class="severity-badge">Medium</span><code>AUTH-006</code><span class="finding-title">Minimum ABAP password length is below current recommendation</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/profile/DEFAULT.PFL · +8</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</dd></div><div><dt>Evidence and impact</dt><dd>login/min_password_lng=8 is below SAP Cloud ALM'#39;s current check value of 12. A client-specific security policy can override this profile value.</dd></div><div><dt>Recommended change</dt><dd>Confirm the effective security policy for every user group and raise the minimum to at least 12 where password logon remains enabled.</dd></div><div><dt>Reference</dt><dd>SAP Cloud ALM supported checks; SAP Help security policy attributes</dd></div></dl></div></details>
<details class="finding search-item severity-high"><summary><span class="severity-badge">High</span><code>CFG-001</code><span class="finding-title">Profile contains a non-empty secret-like parameter</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/profile/DEFAULT.PFL · +18</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</dd></div><div><dt>Evidence and impact</dt><dd>Parameter login/min_password_lng has a literal-looking value. SAPstract deliberately did not record the value.</dd></div><div><dt>Recommended change</dt><dd>Move secrets to the SAP-supported secure store or protected credential mechanism, rotate the value if exposure is possible, and remove it from profiles/backups.</dd></div><div><dt>Reference</dt><dd>OWASP CBAS: filesystem read and credential exposure</dd></div></dl></div></details>
<details class="finding search-item severity-high"><summary><span class="severity-badge">High</span><code>AUTH-002</code><span class="finding-title">Automatic SAP* fallback user is enabled</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/profile/DEFAULT.PFL · +18</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</dd></div><div><dt>Evidence and impact</dt><dd>login/no_automatic_user_sapstar=0 permits the kernel-level SAP* fallback when no SAP* user master record exists in a client.</dd></div><div><dt>Recommended change</dt><dd>Set the parameter to 1, retain and lock a protected SAP* user master in every client, change default credentials, and verify the control in each client without deleting the account.</dd></div><div><dt>Reference</dt><dd>SAP Security Note 68048; ERPScan default-account guidance; SAP Cloud ALM supported checks</dd></div></dl></div></details>
<details class="finding search-item severity-high"><summary><span class="severity-badge">High</span><code>AUTH-001</code><span class="finding-title">RFC authorization checks are disabled</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/profile/DEFAULT.PFL · +18</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</dd></div><div><dt>Evidence and impact</dt><dd>auth/rfc_authority_check=0 disables the S_RFC authorization check for incoming RFC function calls.</dd></div><div><dt>Recommended change</dt><dd>Set a supported non-zero value after tracing and correcting S_RFC roles; evaluate value 9 for function-module-level checks and validate every technical destination.</dd></div><div><dt>Reference</dt><dd>SAP Help: Secure RFCs with Authorizations; SAP Note 931252</dd></div></dl></div></details>
<details class="finding search-item severity-high"><summary><span class="severity-badge">High</span><code>GW-002</code><span class="finding-title">RFC Gateway restrictive fallback is disabled</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/profile/DEFAULT.PFL · +18</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</dd></div><div><dt>Evidence and impact</dt><dd>Profile parameter gw/acl_mode is 0. If secinfo/reginfo are absent or ineffective, external start/registration is unrestricted.</dd></div><div><dt>Recommended change</dt><dd>Set gw/acl_mode=1 and maintain restrictive secinfo and reginfo files; stage and monitor rules before enforcement to avoid business disruption.</dd></div><div><dt>Reference</dt><dd>SAP RFC Gateway security parameters</dd></div></dl></div></details>
<details class="finding search-item severity-high"><summary><span class="severity-badge">High</span><code>GW-007</code><span class="finding-title">RFC Gateway remote program start is enabled</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/profile/DEFAULT.PFL · +18</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</dd></div><div><dt>Evidence and impact</dt><dd>gw/rem_start is neither DISABLED nor SSH_SHELL. External-program start can become operating-system command execution when authorization and secinfo controls fail.</dd></div><div><dt>Recommended change</dt><dd>Set gw/rem_start=DISABLED where possible. If a documented dependency remains, use the SAP-supported SSH_SHELL path and restrictive secinfo rules.</dd></div><div><dt>Reference</dt><dd>OWASP Pentest Playbook: OS command execution; SSVS PT-I-IP-M01-005</dd></div></dl></div></details>
<details class="finding search-item severity-medium"><summary><span class="severity-badge">Medium</span><code>SNC-005</code><span class="finding-title">Secure Network Communications is disabled</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/profile/DEFAULT.PFL · +8</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</dd></div><div><dt>Evidence and impact</dt><dd>snc/enable=0 means the application server does not initialize SNC. Network isolation alone does not provide DIAG/RFC confidentiality or peer authentication.</dd></div><div><dt>Recommended change</dt><dd>Plan SNC with the SAP Cryptographic Library or supported security product, provision the PSE/identity first, set snc/enable=1, and validate protection for each client and destination.</dd></div><div><dt>Reference</dt><dd>SAP Help: snc/enable; OWASP PySAP SNC documentation</dd></div></dl></div></details>
<details class="finding search-item severity-medium"><summary><span class="severity-badge">Medium</span><code>SNC-002</code><span class="finding-title">SNC accepts an insecure connection class</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/profile/DEFAULT.PFL · +8</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</dd></div><div><dt>Evidence and impact</dt><dd>snc/accept_insecure_gui=1 permits this connection class without SNC protection.</dd></div><div><dt>Recommended change</dt><dd>Confirm migration dependencies, then require SNC for sensitive channels and validate every destination before removing compatibility fallback.</dd></div><div><dt>Reference</dt><dd>SAP SNC security parameters; OWASP sncscan research</dd></div></dl></div></details>
<details class="finding search-item severity-medium"><summary><span class="severity-badge">Medium</span><code>SNC-003</code><span class="finding-title">SNC quality of protection is below privacy</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/profile/DEFAULT.PFL · +8</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</dd></div><div><dt>Evidence and impact</dt><dd>snc/data_protection/min=1 permits authentication-only or integrity-only protection rather than data privacy.</dd></div><div><dt>Recommended change</dt><dd>For traffic that carries sensitive data, set and test the SNC protection chain so minimum, default, and maximum values negotiate privacy (3) consistently.</dd></div><div><dt>Reference</dt><dd>SAP SNC QoP documentation; OWASP sncscan</dd></div></dl></div></details>
<details class="finding search-item severity-medium"><summary><span class="severity-badge">Medium</span><code>MS-002</code><span class="finding-title">SAP Message Server administration/monitor function is enabled</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/profile/DEFAULT.PFL · +8</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</dd></div><div><dt>Evidence and impact</dt><dd>ms/monitor has a non-zero value. Reachability and ACLs determine exploitability.</dd></div><div><dt>Recommended change</dt><dd>Disable the function if unused; otherwise restrict binding/firewalls and maintain the relevant message-server ACL file.</dd></div><div><dt>Reference</dt><dd>SAP Message Server security settings</dd></div></dl></div></details>
<details class="finding search-item severity-high"><summary><span class="severity-badge">High</span><code>ICM-006</code><span class="finding-title">ABAP logon tickets are not restricted to HTTPS</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/profile/DEFAULT.PFL · +18</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</dd></div><div><dt>Evidence and impact</dt><dd>login/ticket_only_by_https=0 allows the browser to send logon-ticket and security-session cookies over unencrypted HTTP.</dd></div><div><dt>Recommended change</dt><dd>Enforce HTTPS for the complete authentication path, set the effective value to 1, and confirm secure cookie/session behavior through the supported ICF configuration.</dd></div><div><dt>Reference</dt><dd>SAP Help: Session Security Protection</dd></div></dl></div></details>
<details class="finding search-item severity-high"><summary><span class="severity-badge">High</span><code>ACL-001</code><span class="finding-title">SAP access-control file contains a broad wildcard rule</span><span class="finding-summary-meta">/usr/sap/saprouter/saprouttab · +18</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/saprouter/saprouttab</dd></div><div><dt>Evidence and impact</dt><dd>A permissive wildcard pattern was detected in saprouttab, including positional SAProuter target-host wildcards; rule contents were not copied into the report.</dd></div><div><dt>Recommended change</dt><dd>Review rules in order, replace broad permits with explicit program/user/host or route entries, test in logging/simulation mode where supported, and reload safely.</dd></div><div><dt>Reference</dt><dd>SAP RFC Gateway guidance; SAP Note 1895350; SEC Consult CVE-2022-27668</dd></div></dl></div></details>
</div></div></details>
<details id="findings-filesystem" class="report-section finding-section"><summary><h2>Files & executable integrity findings</h2><span class="count-badge">1 finding(s) · 18/100 · grade B</span></summary><div class="section-body"><div class="section-head"><div><strong>Limited hardening gaps</strong><div class="muted">0 critical · 1 high · 0 medium · 0 low</div></div><input class="filter" placeholder="Filter Files & executable integrity findings…" data-target="finding-list-filesystem"></div><div class="finding-list" id="finding-list-filesystem">
<details class="finding search-item severity-high"><summary><span class="severity-badge">High</span><code>FILE-005</code><span class="finding-title">Secret-bearing SAP data is readable by everyone</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/global/security/data/SSFS_PRD.DAT · +18</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/global/security/data/SSFS_PRD.DAT</dd></div><div><dt>Evidence and impact</dt><dd>Mode 644 allows arbitrary local users to copy encrypted or credential-bearing material for offline analysis.</dd></div><div><dt>Recommended change</dt><dd>Remove other-read access, restrict parent-directory traversal, and review whether the matching keys or credentials were also exposed.</dd></div><div><dt>Reference</dt><dd>OWASP CBAS: filesystem read attack paths</dd></div></dl></div></details>
</div></div></details>
<details id="findings-secrets" class="report-section finding-section"><summary><h2>SSFS, credentials & client data findings</h2><span class="count-badge">4 finding(s) · 86/100 · grade F</span></summary><div class="section-body"><div class="section-head"><div><strong>Critical remediation priority</strong><div class="muted">2 critical · 1 high · 1 medium · 0 low</div></div><input class="filter" placeholder="Filter SSFS, credentials & client data findings…" data-target="finding-list-secrets"></div><div class="finding-list" id="finding-list-secrets">
<details class="finding search-item severity-critical"><summary><span class="severity-badge">Critical</span><code>SSFS-001</code><span class="finding-title">SSFS key material is writable by everyone</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/global/security/data/SSFS_PRD.KEY · +30</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/global/security/data/SSFS_PRD.KEY</dd></div><div><dt>Evidence and impact</dt><dd>Mode 666 permits other users to alter master-key or local-protection material.</dd></div><div><dt>Recommended change</dt><dd>Restrict the file and its parent path to the SAP service owner and only the explicitly required administration group; validate with SAP tooling after correcting ownership.</dd></div><div><dt>Reference</dt><dd>SAP SSFS least-privilege guidance</dd></div></dl></div></details>
<details class="finding search-item severity-high"><summary><span class="severity-badge">High</span><code>SSFS-002</code><span class="finding-title">SSFS key material is group-writable</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/global/security/data/SSFS_PRD.KEY · +18</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/global/security/data/SSFS_PRD.KEY</dd></div><div><dt>Evidence and impact</dt><dd>Mode 666 allows members of group fremen to replace key material.</dd></div><div><dt>Recommended change</dt><dd>Confirm the group is operationally required and tightly controlled; otherwise remove group-write and keep matched SSFS data/key backups.</dd></div><div><dt>Reference</dt><dd>SAP SSFS least-privilege guidance</dd></div></dl></div></details>
<details class="finding search-item severity-critical"><summary><span class="severity-badge">Critical</span><code>SSFS-003</code><span class="finding-title">SSFS key material is readable by everyone</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/global/security/data/SSFS_PRD.KEY · +30</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/global/security/data/SSFS_PRD.KEY</dd></div><div><dt>Evidence and impact</dt><dd>Mode 666 exposes master-key or key-protection material to arbitrary local users.</dd></div><div><dt>Recommended change</dt><dd>Remove all access for other users immediately, review access logs and local accounts, and rotate/re-encrypt the secure store if disclosure cannot be excluded.</dd></div><div><dt>Reference</dt><dd>SAP SSFS least-privilege guidance</dd></div></dl></div></details>
<details class="finding search-item severity-medium"><summary><span class="severity-badge">Medium</span><code>SSFS-004</code><span class="finding-title">SSFS key material is group-readable</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/global/security/data/SSFS_PRD.KEY · +8</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/global/security/data/SSFS_PRD.KEY</dd></div><div><dt>Evidence and impact</dt><dd>Mode 666 exposes key material to every member of group fremen.</dd></div><div><dt>Recommended change</dt><dd>Confirm all group members require access. Prefer owner-only read access where the SAP deployment permits it.</dd></div><div><dt>Reference</dt><dd>SAP SSFS least-privilege guidance</dd></div></dl></div></details>
</div></div></details>
<details id="findings-operations" class="report-section finding-section"><summary><h2>Operations, logging & command execution findings</h2><span class="count-badge">3 finding(s) · 34/100 · grade C</span></summary><div class="section-body"><div class="section-head"><div><strong>Material hardening gaps</strong><div class="muted">0 critical · 1 high · 2 medium · 0 low</div></div><input class="filter" placeholder="Filter Operations, logging & command execution findings…" data-target="finding-list-operations"></div><div class="finding-list" id="finding-list-operations">
<details class="finding search-item severity-high"><summary><span class="severity-badge">High</span><code>OSCMD-001</code><span class="finding-title">ABAP CALL SYSTEM is enabled</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/profile/DEFAULT.PFL · +18</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</dd></div><div><dt>Evidence and impact</dt><dd>rdisp/call_system=1 enables a legacy path that executes operating-system commands in the SAP service-user context.</dd></div><div><dt>Recommended change</dt><dd>Set rdisp/call_system=0 after dependency testing; use controlled SXPG commands with least-privilege authorization for required integrations.</dd></div><div><dt>Reference</dt><dd>OWASP Pentest Playbook: OS command execution; SAP KBA 2879860</dd></div></dl></div></details>
<details class="finding search-item severity-medium"><summary><span class="severity-badge">Medium</span><code>LOG-001</code><span class="finding-title">ABAP table-change logging is disabled</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/profile/DEFAULT.PFL · +8</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</dd></div><div><dt>Evidence and impact</dt><dd>rec/client is OFF, so changes to log-enabled tables may not be captured.</dd></div><div><dt>Recommended change</dt><dd>Define the required clients (or ALL where policy requires), confirm critical tables have logging enabled, protect the logs, and monitor retention.</dd></div><div><dt>Reference</dt><dd>OWASP SSVS DT-P-AE-M01-004</dd></div></dl></div></details>
<details class="finding search-item severity-medium"><summary><span class="severity-badge">Medium</span><code>LOG-002</code><span class="finding-title">Static Security Audit Log profile is disabled</span><span class="finding-summary-meta">/usr/sap/PRD/SYS/profile/DEFAULT.PFL · +8</span></summary><div class="finding-body"><dl><div><dt>Affected asset</dt><dd>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</dd></div><div><dt>Evidence and impact</dt><dd>rsau/enable=0 disables the static profile switch for the ABAP Security Audit Log. A dynamic configuration can differ, so this is evidence of a profile gap rather than proof that no audit events are recorded.</dd></div><div><dt>Recommended change</dt><dd>Review the effective configuration and filters in SM19/RSAU_CONFIG on every application server, enable the Security Audit Log where required, and validate protected retention and central monitoring in SM20.</dd></div><div><dt>Reference</dt><dd>SAP Security Audit Log documentation; SAP Cloud ALM supported checks</dd></div></dl></div></details>
</div></div></details>
<details id="systems" class="report-section"><summary><h2>SAP systems</h2><span class="count-badge">1 system(s)</span></summary><div class="section-body"><div class="section-head"><div class="muted">SID and instance footprints</div><input class="filter" placeholder="Filter systems…" data-target="systems-table"></div><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table id="systems-table"><thead><tr><th>SID</th><th>Stack</th><th>Instances</th><th>Root</th><th>Source</th></tr></thead><tbody>
<tr class="search-row"><td>PRD</td><td>SAP NetWeaver</td><td></td><td>/usr/sap/PRD</td><td>/usr/sap directory</td></tr>
</tbody></table></div></div></details>
<details id="runtime" class="report-section"><summary><h2>Raw services and processes</h2><span class="count-badge">1 service(s) · 4 process(es)</span></summary><div class="section-body"><div class="section-head"><div class="muted">Underlying service-manager and process evidence; use the categorized catalog above for analysis</div><input class="filter" placeholder="Filter services/processes…" data-target="service-tables"></div><div id="service-tables">
<details class="technical-group" open><summary><span>Services</span><span class="summary-meta">1 instance(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table><thead><tr><th>Name</th><th>State</th><th>Start mode</th><th>Account</th><th>Definition/path</th><th>Description</th></tr></thead><tbody>
<tr class="search-row"><td>SAPPRD_00.service</td><td>active/running</td><td>systemd</td><td></td><td></td><td>SAP PRD Instance 00</td></tr>
</tbody></table></div></div></details><details class="technical-group"><summary><span>Processes</span><span class="summary-meta">4 instance(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table><thead><tr><th>PID</th><th>User</th><th>Group</th><th>Name</th><th>Executable</th><th>Command</th><th>Component</th></tr></thead><tbody>
<tr class="search-row"><td>200</td><td>prdadm</td><td>sapsys</td><td>disp+work</td><td></td><td>disp+work pf=/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>SAP Dispatcher/Work Process</td></tr>
<tr class="search-row"><td>201</td><td>prdadm</td><td>sapsys</td><td>gwrd</td><td>/opt/lisan-agents/bin/codex</td><td>gwrd pf=/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>SAP RFC Gateway</td></tr>
<tr class="search-row"><td>202</td><td>prdadm</td><td>sapsys</td><td>sapstartsrv</td><td>/opt/lisan-agents/bin/codex</td><td>sapstartsrv pf=/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>SAP Start Service</td></tr>
<tr class="search-row"><td>300</td><td>prdadm</td><td>sapsys</td><td>saprouter</td><td></td><td>saprouter -r -R /usr/sap/saprouter/saprouttab</td><td>SAProuter</td></tr>
</tbody></table></div></div></details></div></div></details>
<details id="sockets" class="report-section"><summary><h2>Listening endpoints and open connections</h2><span class="count-badge">4 listener(s) · 1 connection(s) · 0 uncorroborated</span></summary><div class="section-body"><div class="section-head"><div class="muted">Only process-owned or host-correlated sockets are promoted as SAP evidence; ambiguous port matches remain separate and cannot create findings.</div><input class="filter" placeholder="Filter network evidence…" data-target="socket-groups"></div><div id="socket-groups"><details class="technical-group" open><summary><span>Listening endpoints</span><span class="summary-meta">4 observation(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table><thead><tr><th>Classification</th><th>Transport</th><th>Protocol</th><th>State</th><th>Local</th><th>Remote</th><th>Exposure</th><th>PID</th><th>Process</th><th>Service</th><th>Confidence</th><th>Evidence basis</th></tr></thead><tbody>
<tr class="search-row"><td>SAP Dispatcher / SAP DIAG or Enqueue</td><td>NI/DIAG</td><td>TCP</td><td>LISTEN</td><td>0.0.0.0:3200</td><td>0.0.0.0:*</td><td>all-interfaces</td><td>200</td><td>disp+work</td><td></td><td>high</td><td>Socket owned by collected SAP process PID 200</td></tr><tr class="search-row"><td>SAP RFC Gateway</td><td>RFC/NI (typically unencrypted)</td><td>TCP</td><td>LISTEN</td><td>0.0.0.0:3300</td><td>0.0.0.0:*</td><td>all-interfaces</td><td>201</td><td>gwrd</td><td></td><td>high</td><td>Socket owned by collected SAP process PID 201</td></tr><tr class="search-row"><td>SAP Start Service HTTP</td><td>HTTP/SOAP</td><td>TCP</td><td>LISTEN</td><td>0.0.0.0:50013</td><td>0.0.0.0:*</td><td>all-interfaces</td><td>202</td><td>sapstartsrv</td><td></td><td>high</td><td>Socket owned by collected SAP process PID 202</td></tr><tr class="search-row"><td>SAProuter</td><td>NI/Router</td><td>TCP</td><td>LISTEN</td><td>0.0.0.0:3299</td><td>0.0.0.0:*</td><td>all-interfaces</td><td>300</td><td>saprouter</td><td></td><td>high</td><td>Socket owned by collected SAP process PID 300</td></tr></tbody></table></div></div></details><details class="technical-group" open><summary><span>Established and open connections</span><span class="summary-meta">1 observation(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table><thead><tr><th>Classification</th><th>Transport</th><th>Protocol</th><th>State</th><th>Local</th><th>Remote</th><th>Exposure</th><th>PID</th><th>Process</th><th>Service</th><th>Confidence</th><th>Evidence basis</th></tr></thead><tbody>
<tr class="search-row"><td>SAP RFC Gateway</td><td>RFC/NI (typically unencrypted)</td><td>TCP</td><td>ESTAB</td><td>10.20.30.10:3300</td><td>10.20.40.25:49152</td><td>connected</td><td>201</td><td>gwrd</td><td></td><td>high</td><td>Socket owned by collected SAP process PID 201</td></tr></tbody></table></div></div></details><details class="technical-group"><summary><span>Uncorroborated SAP-port candidates</span><span class="summary-meta">0 candidate(s), excluded from findings and topology</span></summary><div class="technical-group-body"><p class="muted">These are retained to avoid losing possible evidence when ownership is unavailable, but a port number by itself does not establish SAP.</p><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table><thead><tr><th>Candidate classification</th><th>Transport</th><th>Protocol</th><th>State</th><th>Local</th><th>Remote</th><th>PID</th><th>Process</th><th>Reason not promoted</th></tr></thead><tbody></tbody></table></div></div></details></div></div></details>
<details id="ssfs" class="report-section"><summary><h2>SAP secure stores (SSFS)</h2><span class="count-badge">2 artifact(s)</span></summary><div class="section-body"><div class="section-head"><div class="muted">Metadata-only coverage: ABAP/RSEC, HANA instance, HANA System-PKI, hdbuserstore, enhanced LKY, and Cloud Connector</div><input class="filter" placeholder="Filter SSFS…" data-target="ssfs-table"></div>
<p class="notice">The presence of a <code>.DAT</code> and <code>.KEY</code> pair is operational evidence—not a guarantee of secure key lifecycle. Conversely, a missing key can mean a separate configured path; Cloud Connector and default-key contexts require product-specific confirmation. No record names, values, HMAC keys, master keys, or decrypted bytes are included.</p>
<details class="technical-group" open><summary><span>Secure-store artifacts</span><span class="summary-meta">2 metadata record(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table id="ssfs-table"><thead><tr><th>Family</th><th>SID/store</th><th>Role</th><th>Path</th><th>Bytes</th><th>Owner</th><th>Group</th><th>Mode</th><th>Safe inspection detail</th></tr></thead><tbody>
<tr class="search-row"><td>Generic SAP SSFS</td><td>PRD</td><td>SSFS key</td><td>/usr/sap/PRD/SYS/global/security/data/SSFS_PRD.KEY</td><td>56</td><td>fremen</td><td>fremen</td><td>666</td><td>Individual master-key material; header not recognized; key bytes not read</td></tr>
<tr class="search-row"><td>Generic SAP SSFS</td><td>PRD</td><td>SSFS data</td><td>/usr/sap/PRD/SYS/global/security/data/SSFS_PRD.DAT</td><td>62</td><td>fremen</td><td>fremen</td><td>644</td><td>Active secure-store data; 0 record(s); empty or unrecognized data file; values not read</td></tr>
</tbody></table></div></div></details></div></details>
<details id="tools" class="report-section"><summary><h2>SAP tools</h2><span class="count-badge">0 tool(s)</span></summary><div class="section-body"><div class="section-head"><div class="muted">Administration and runtime binaries; not executed</div><input class="filter" placeholder="Filter tools…" data-target="tools-table"></div><details class="technical-group" open><summary><span>Tool instances and integrity metadata</span><span class="summary-meta">0 binary record(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table id="tools-table"><thead><tr><th>Name</th><th>Capability</th><th>Path</th><th>Source</th><th>Owner</th><th>Group</th><th>Mode</th><th>Bytes</th><th>SHA-256</th></tr></thead><tbody>
</tbody></table></div></div></details></div></details>
<details id="profiles" class="report-section"><summary><h2>Profiles and parameters</h2><span class="count-badge">17 parameter(s)</span></summary><div class="section-body"><div class="section-head"><div class="muted">Security-relevant local configuration; secret-like values are always redacted</div><input class="filter" placeholder="Filter parameters…" data-target="profiles-table"></div><details class="technical-group" open><summary><span>Observed parameter instances</span><span class="summary-meta">17 record(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table id="profiles-table"><thead><tr><th>File</th><th>Parameter</th><th>Value</th><th>Source</th></tr></thead><tbody>
<tr class="search-row"><td>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>login/min_password_lng</td><td>[REDACTED: non-empty]</td><td>filesystem</td></tr>
<tr class="search-row"><td>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>login/no_automatic_user_sapstar</td><td>0</td><td>filesystem</td></tr>
<tr class="search-row"><td>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>auth/rfc_authority_check</td><td>0</td><td>filesystem</td></tr>
<tr class="search-row"><td>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>gw/acl_mode</td><td>0</td><td>filesystem</td></tr>
<tr class="search-row"><td>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>gw/monitor</td><td>1</td><td>filesystem</td></tr>
<tr class="search-row"><td>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>gw/rem_start</td><td>REMOTE_SHELL</td><td>filesystem</td></tr>
<tr class="search-row"><td>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>snc/enable</td><td>0</td><td>filesystem</td></tr>
<tr class="search-row"><td>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>snc/accept_insecure_gui</td><td>1</td><td>filesystem</td></tr>
<tr class="search-row"><td>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>snc/data_protection/min</td><td>1</td><td>filesystem</td></tr>
<tr class="search-row"><td>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>ms/monitor</td><td>1</td><td>filesystem</td></tr>
<tr class="search-row"><td>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>rdisp/call_system</td><td>1</td><td>filesystem</td></tr>
<tr class="search-row"><td>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>rec/client</td><td>OFF</td><td>filesystem</td></tr>
<tr class="search-row"><td>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>rsau/enable</td><td>0</td><td>filesystem</td></tr>
<tr class="search-row"><td>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>icm/HTTP/error_templ_path</td><td>SHOW_DETAIL</td><td>filesystem</td></tr>
<tr class="search-row"><td>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>icm/HTTP/server_header</td><td>1</td><td>filesystem</td></tr>
<tr class="search-row"><td>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>login/ticket_only_by_https</td><td>0</td><td>filesystem</td></tr>
<tr class="search-row"><td>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>rdisp/start</td><td>/bin/echo showcase</td><td>filesystem</td></tr>
</tbody></table></div></div></details></div></details>
<details id="paths" class="report-section"><summary><h2>Files, directories, and permissions</h2><span class="count-badge">9 path(s)</span></summary><div class="section-body"><div class="section-head"><div class="muted">Filesystem evidence split into technical categories</div><input class="filter" placeholder="Filter path evidence…" data-target="path-groups"></div><div id="path-groups"><details class="technical-group path-category"><summary><span>ACL</span><span class="summary-meta">3 path(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table><thead><tr><th>Path</th><th>Type</th><th>Owner</th><th>Group</th><th>Mode</th><th>Bytes</th><th>Modified</th><th>Note</th></tr></thead><tbody><tr class="search-row"><td>/usr/sap/PRD/SYS/global/security/data/reginfo</td><td>regular file</td><td>fremen</td><td>fremen</td><td>644</td><td>14</td><td>2026-08-10 05:46:54</td><td>reginfo</td></tr><tr class="search-row"><td>/usr/sap/PRD/SYS/global/security/data/secinfo</td><td>regular file</td><td>fremen</td><td>fremen</td><td>644</td><td>14</td><td>2026-08-10 05:46:54</td><td>secinfo</td></tr><tr class="search-row"><td>/usr/sap/saprouter/saprouttab</td><td>regular file</td><td>fremen</td><td>fremen</td><td>644</td><td>8</td><td>2026-08-10 05:46:54</td><td>saprouttab</td></tr></tbody></table></div></div></details><details class="technical-group path-category"><summary><span>Executable</span><span class="summary-meta">1 path(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table><thead><tr><th>Path</th><th>Type</th><th>Owner</th><th>Group</th><th>Mode</th><th>Bytes</th><th>Modified</th><th>Note</th></tr></thead><tbody><tr class="search-row"><td>/opt/lisan-agents/bin/codex</td><td>regular file</td><td>root</td><td>root</td><td>755</td><td>269360944</td><td>2026-08-10 04:49:26</td><td>Running SAP RFC Gateway binary</td></tr></tbody></table></div></div></details><details class="technical-group path-category"><summary><span>Profile</span><span class="summary-meta">1 path(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table><thead><tr><th>Path</th><th>Type</th><th>Owner</th><th>Group</th><th>Mode</th><th>Bytes</th><th>Modified</th><th>Note</th></tr></thead><tbody><tr class="search-row"><td>/usr/sap/PRD/SYS/profile/DEFAULT.PFL</td><td>regular file</td><td>fremen</td><td>fremen</td><td>644</td><td>423</td><td>2026-08-10 05:46:54</td><td>SAP profile/configuration</td></tr></tbody></table></div></div></details><details class="technical-group path-category"><summary><span>SAP root</span><span class="summary-meta">1 path(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table><thead><tr><th>Path</th><th>Type</th><th>Owner</th><th>Group</th><th>Mode</th><th>Bytes</th><th>Modified</th><th>Note</th></tr></thead><tbody><tr class="search-row"><td>/usr/sap</td><td>directory</td><td>fremen</td><td>fremen</td><td>755</td><td>4096</td><td>2026-08-10 05:46:54</td><td>Standard SAP installation root</td></tr></tbody></table></div></div></details><details class="technical-group path-category"><summary><span>SAP system</span><span class="summary-meta">1 path(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table><thead><tr><th>Path</th><th>Type</th><th>Owner</th><th>Group</th><th>Mode</th><th>Bytes</th><th>Modified</th><th>Note</th></tr></thead><tbody><tr class="search-row"><td>/usr/sap/PRD</td><td>directory</td><td>fremen</td><td>fremen</td><td>755</td><td>4096</td><td>2026-08-10 05:46:54</td><td>SID PRD</td></tr></tbody></table></div></div></details><details class="technical-group path-category"><summary><span>SSFS data</span><span class="summary-meta">1 path(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table><thead><tr><th>Path</th><th>Type</th><th>Owner</th><th>Group</th><th>Mode</th><th>Bytes</th><th>Modified</th><th>Note</th></tr></thead><tbody><tr class="search-row"><td>/usr/sap/PRD/SYS/global/security/data/SSFS_PRD.DAT</td><td>regular file</td><td>fremen</td><td>fremen</td><td>644</td><td>62</td><td>2026-08-10 05:46:54</td><td>Generic SAP SSFS; secret-bearing metadata only</td></tr></tbody></table></div></div></details><details class="technical-group path-category"><summary><span>SSFS key</span><span class="summary-meta">1 path(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table><thead><tr><th>Path</th><th>Type</th><th>Owner</th><th>Group</th><th>Mode</th><th>Bytes</th><th>Modified</th><th>Note</th></tr></thead><tbody><tr class="search-row"><td>/usr/sap/PRD/SYS/global/security/data/SSFS_PRD.KEY</td><td>regular file</td><td>fremen</td><td>fremen</td><td>666</td><td>56</td><td>2026-08-10 05:46:54</td><td>Generic SAP SSFS; secret-bearing metadata only</td></tr></tbody></table></div></div></details></div></div></details>
<details id="assessment" class="report-section"><summary><h2>Assessment map</h2><span class="count-badge">22 area(s)</span></summary><div class="section-body"><div class="section-head"><div class="muted">Automated evidence and the authenticated or active work still required—absence of evidence is never shown as a pass</div><input class="filter" placeholder="Filter assessment map…" data-target="assessment-table"></div><details class="technical-group" open><summary><span>Coverage areas and required follow-up</span><span class="summary-meta">22 area(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table id="assessment-table"><thead><tr><th>Area</th><th>Status</th><th>Evidence collected</th><th>Required next step</th><th>Research source</th></tr></thead><tbody>
<tr class="search-row"><td>Host footprint and permissions</td><td>automated</td><td>Processes, services, sockets, paths, owners, modes/ACLs, profiles, tools, and hashes</td><td>Review every finding and repeat with elevation if collection coverage is partial.</td><td>OWASP SSVS OS controls; PySAP recognition</td></tr>
<tr class="search-row"><td>RFC Gateway and Message Server</td><td>automated + manual</td><td>Local ports, gateway/message profiles, secinfo/reginfo/prxyinfo/message ACL metadata</td><td>Use an authorized segmented-zone test to prove external reachability and effective ACL behavior.</td><td>OWASP SSVS; Attack Surface Discovery; Pentest Playbook</td></tr>
<tr class="search-row"><td>Dispatcher, DIAG, SNC, SAProuter</td><td>automated + manual</td><td>Port/profile/SNC/saprouttab evidence</td><td>Use authorized sncscan/SAP tooling to prove negotiated QoP and external route exposure.</td><td>OWASP sncscan; HoneySAP; Pentest Playbook</td></tr>
<tr class="search-row"><td>ICM, IGS, Start Service, Web Dispatcher</td><td>automated + manual</td><td>Listener, error/header, file alias, IGS admin, protected-webmethod, ACL, and local port evidence</td><td>Perform approved HTTP/TLS and authentication validation from every relevant trust zone.</td><td>Attack Surface Discovery; Pentest Playbook; OWASP SSVS</td></tr>
<tr class="search-row"><td>SAP Cloud Connector and BTP</td><td>footprint + manual</td><td>SCC service/process/config/SSFS/keystore paths and local listener evidence</td><td>Review SCC patch/JDK, HA, trust, admin roles, alerts, destinations, identity providers, and BTP controls in the authenticated consoles.</td><td>OWASP SSVS BTP controls; CBAS exposure research</td></tr>
<tr class="search-row"><td>SAP HANA and ASE</td><td>footprint + manual</td><td>Processes, ports, paths, INI/SSFS/secure user-store metadata, and local permissions</td><td>Authenticate with read-only audit roles to review users, roles, password policy, audit policy, tenants, TLS, replication, and patch level.</td><td>OWASP SSVS HANA controls; Attack Surface Discovery</td></tr>
<tr class="search-row"><td>ABAP identity and authorization</td><td>manual/authenticated</td><td>Not derivable reliably from host files</td><td>Review standard users, SAP_ALL, S_RFC/S_RFCACL, critical transactions/tables, password/hash policy, RFC destinations, and system trust.</td><td>OWASP SAPKiln; SSVS; Pentest Playbook</td></tr>
<tr class="search-row"><td>ABAP code and business data</td><td>manual/authenticated</td><td>Host artifacts cannot prove authorization checks, injection resistance, path traversal, or data classification</td><td>Run SCI/ATC/CVA and controlled reviews for filesystem, database, dynamic code, OS commands, RFC modules, and sensitive data access.</td><td>OWASP SSVS IY controls; Pentest Playbook</td></tr>
<tr class="search-row"><td>Logging and detection</td><td>partial + manual</td><td>Local audit/system/trace file presence, metadata, and selected logging profiles</td><td>Validate SAL, SM21, table logging, RAL, workload/user reports, HANA/Java/BTP audit, central forwarding, alerts, integrity, and retention.</td><td>OWASP SSVS DT controls</td></tr>
<tr class="search-row"><td>Transports and software supply chain</td><td>automated + manual</td><td>Transport/archive/tool paths, permissions, and tool hashes</td><td>Review transport creation/import authorization, approvals, signatures, import routes, client libraries, and patch/Security Note posture.</td><td>Pentest Playbook; OWASP SSVS</td></tr>
<tr class="search-row"><td>SSFS, PSE, credentials, and key lifecycle</td><td>metadata + manual</td><td>All known SSFS families, PSE/credential/keystore artifacts, pair/header/type and permission metadata</td><td>Validate with official product tools; review generation, rotation, backup, recovery, separation, certificate expiry, and supported SCC key mode.</td><td>SAP SSFS/HANA guidance; OWASP SSVS crypto controls; PySAP formats</td></tr>
<tr class="search-row"><td>SAP GUI clients and input history</td><td>automated footprint + manual</td><td>Known local history paths and metadata; no history content read</td><td>Patch SAP GUI, apply SAP Notes for CVE-2025-0055/0056, disable or minimize history, and exclude sensitive fields.</td><td>OWASP CBAS SAP GUI history research</td></tr>
<tr class="search-row"><td>External attack surface</td><td>not performed</td><td>A host-local listener is not proof of Internet or cross-zone reachability</td><td>Perform a separately authorized external inventory for SAProuter, Dispatcher, Gateway, Message Server, SCC, Java, HANA, ASE, ICM/IGS, Start Service, and Web Dispatcher.</td><td>CBAS Internet Scan 2025/2026; Attack Surface Discovery</td></tr>
<tr class="search-row"><td>Resilience and recovery</td><td>manual</td><td>Local footprints may show enqueue replication components but cannot prove failover, backups, or recovery objectives</td><td>Validate ABAP/Java enqueue replication, SCC HA, HANA replication, backup protection, restore tests, and incident procedures.</td><td>OWASP SSVS availability controls; Security Matrix</td></tr>
<tr class="search-row"><td>Governance and response</td><td>manual</td><td>Policies, ownership, risk acceptance, detection workflows, and recovery exercises are organizational evidence</td><td>Assess all Integration, Platform, Access, and Customization areas across Identify, Protect, Detect, Respond, and Recover.</td><td>CBAS Security Matrix</td></tr>
<tr class="search-row"><td>RFC callbacks, UCON, and trusted relationships</td><td>profile evidence + authenticated</td><td>Observed callback, UCON, authorization-check, legacy-ticket, and SNC parameters</td><td>Review SM59 callback allow-lists, S_RFC/S_RFCACL, UCON phase/function allow-lists, trusted-system relationships, technical users, and Security Audit Log events. Remove wildcard functions.</td><td>SAP RFC documentation; Onapsis callback research; SEC Consult RFC research</td></tr>
<tr class="search-row"><td>Standard users and password policy</td><td>profile evidence + authenticated</td><td>Observed SAP* fallback and password-policy parameters; no password values or login attempts</td><td>For every client, review SAP*, DDIC, SAPCPIC, TMSADM, EARLYWATCH and solution-specific users; lock/retain required accounts, change defaults, remove excess profiles, and confirm effective security policies.</td><td>ERPScan default-account guide; HackTricks references; SAP Cloud ALM</td></tr>
<tr class="search-row"><td>SAP HTTP endpoints and information disclosure</td><td>not actively tested</td><td>ICM/Java/IGS/Start Service/Web Dispatcher process, listener, artifact, and profile evidence</td><td>From each approved trust zone, validate /sap/public/info, WebGUI, Fiori, NWA, IGS status/admin, Dispatcher login info, SOAP/WebSocket RFC, Start Service methods, headers, TLS, and authentication without brute force.</td><td>SecuritySilverbacks Attack Surface Discovery templates</td></tr>
<tr class="search-row"><td>SAP Security Notes and protocol CVEs</td><td>manual/authenticated</td><td>Host-local filenames and banners are not treated as patch proof</td><td>Use SAP for Me/System Recommendations and component inventory to verify applicable Notes, including 3158375, 3007182, 3044754, 3032624, 3089413 and current corrections for CVE-2018-2392, CVE-2021-40495, CVE-2022-27668, and CVE-2025-31324.</td><td>SecuritySilverbacks templates; SEC Consult; SAP Security Notes</td></tr>
<tr class="search-row"><td>Java secure store, descriptors, and Download Manager</td><td>metadata + manual</td><td>SecStore.properties/SecStore.key, dlmanager.conf, PSE/keystore, archive, and Java host artifact metadata when present</td><td>Verify strict pair permissions, supported credential protection and fixed Download Manager release; review web.xml, webdynpro.xml and portalapp.xml authorization, upload, XXE/SSRF, invoker, and logging controls.</td><td>Breaking SAP Portal; Hardcore SAP Pentesting; OWASP PySAP Download Manager</td></tr>
<tr class="search-row"><td>SAProuter routing and administration</td><td>automated + active/manual</td><td>Process flags, 3299 listener, saprouttab metadata/wildcards, and local tool version/hash</td><td>Remove -X and target wildcards, restrict 3299 to required peers, require SNC where appropriate, inspect dev_rout, verify Note 3158375/current kernel, and perform an authorized route/admin test.</td><td>Rapid7 Piercing SAProuter; SEC Consult CVE-2022-27668</td></tr>
<tr class="search-row"><td>Enqueue and cluster coordination</td><td>automated + manual</td><td>Enqueue/replication process and listener evidence</td><td>Restrict Enqueue and replication listeners to explicit cluster peers, validate monitor authorization and current patches, and test failover without exposing administrative operations.</td><td>OWASP PySAP Enqueue; SAP availability guidance</td></tr>
</tbody></table></div></div></details></div></details>
<details id="coverage" class="report-section"><summary><h2>Coverage and limitations</h2><span class="count-badge">13 check(s)</span></summary><div class="section-body"><p class="muted">Use this section when interpreting a clean result.</p><details class="technical-group" open><summary><span>Collection coverage</span><span class="summary-meta">13 check(s)</span></summary><div class="technical-group-body"><div class="scroll-hint">Scroll horizontally to see all columns →</div><div class="table-wrap"><table><thead><tr><th>Check</th><th>Status</th><th>Detail</th></tr></thead><tbody>
<tr class="search-row"><td>Host metadata</td><td>complete</td><td>Host=prd-app-01.example.test; OS=Ubuntu 26.04 LTS; kernel=6.10.14-linuxkit; user=fremen; elevated=no; root=/tmp/sapstract-example-fixture</td></tr>
<tr class="search-row"><td>Privilege</td><td>partial</td><td>Not elevated: process ownership, sockets, ACLs, and protected paths may be incomplete</td></tr>
<tr class="search-row"><td>SAP systems</td><td>complete</td><td>Standard /usr/sap and /sapmnt layouts plus sapservices inspected</td></tr>
<tr class="search-row"><td>Processes</td><td>complete</td><td>Local process table inspected; command lines may be permission-limited</td></tr>
<tr class="search-row"><td>Services</td><td>complete</td><td>Local service manager and init definitions inspected</td></tr>
<tr class="search-row"><td>Sockets</td><td>complete</td><td>ss -tunap; process attribution depends on privileges</td></tr>
<tr class="search-row"><td>Socket correlation</td><td>complete</td><td>Every recorded SAP socket was supported by process ownership, a discovered instance, or a dedicated SAP service port</td></tr>
<tr class="search-row"><td>Profiles and ACLs</td><td>complete</td><td>Known profile and ACL names under SAP roots inspected; secret-like values redacted</td></tr>
<tr class="search-row"><td>SSFS</td><td>complete</td><td>ABAP/RSEC, HANA instance, HANA System-PKI, hdbuserstore, enhanced LKY, and SCC naming/layouts inspected; values and key bytes were not read</td></tr>
<tr class="search-row"><td>Tools</td><td>complete</td><td>PATH and standard SAP roots inspected; binaries were not executed</td></tr>
<tr class="search-row"><td>Security artifacts</td><td>complete</td><td>Broad artifact names inspected only under SAP roots; user profiles limited to the documented SAP GUI history layout</td></tr>
<tr class="search-row"><td>Service topology</td><td>derived</td><td>Nodes, edges, capabilities, service categories, and database placement were inferred from collected local evidence; no connection was initiated.</td></tr>
<tr class="search-row"><td>OWASP CBAS and SAP reference corpus</td><td>cataloged</td><td>Root page; 9 linked projects/resources; 74 playbook pages; 35 active Attack Surface checks plus 11 workflows; PySAP docs/notebooks/examples; every HackTricks SAP/SAProuter reference; SSVS, SAPKiln, HoneySAP, sncscan, Security Matrix, and research papers mapped in docs</td></tr>
</tbody></table></div></div></details>
<details class="technical-group"><summary><span>Scoring model</span><span class="summary-meta">How section and aggregate scores work</span></summary><div class="technical-group-body"><p>Each unique affected asset contributes Critical 30, High 18, Medium 8, or Low 3 points. Each section is capped independently at 100; the backward-compatible aggregate index is also capped at 100. Grade A is 0–9, B 10–24, C 25–49, D 50–74, and F 75–100. A score is a prioritization aid, not a probability of compromise. Duplicate evidence for the same rule and asset is de-duplicated.</p></div></details>
<details class="technical-group"><summary><span>Assessment boundary</span><span class="summary-meta">What this host-local pass cannot prove</span></summary><div class="technical-group-body"><p>This host-local pass can prove file metadata, selected profile values, running processes/services, and local socket state at collection time. It cannot prove firewall reachability from another zone, SAP authorization design, current Security Notes, TLS cipher quality, SNC use on each session, database role design, ABAP code security, or whether an observed version is vulnerable. Those require authenticated and change-controlled follow-up.</p></div></details>
<details class="technical-group"><summary><span>Research basis</span><span class="summary-meta">References behind recognition and risk context</span></summary><div class="technical-group-body"><p>Service recognition and threat context are aligned with SAP documentation, OWASP Core Business Application Security, the community SAP Pentest Playbook, and PySAP protocol/file-format modules. SAPstract has no PySAP, Scapy, Python, browser-CDN, or network-scanner runtime dependency.</p></div></details>
</div></details>
<footer>SAPstract 2.2.0 · JSON companion: example.json · Evidence may contain sensitive topology; protect the report.</footer>
</div>
<script>
const root=document.documentElement,themeButton=document.getElementById('theme-toggle');
function syncThemeButton(){themeButton.textContent=root.dataset.theme==='dark'?'Light theme':'Dark theme'}
syncThemeButton();
themeButton.addEventListener('click',()=>{
root.dataset.theme=root.dataset.theme==='dark'?'light':'dark';
try{localStorage.setItem('sapstract-theme',root.dataset.theme)}catch(e){}
syncThemeButton();
});
document.querySelectorAll('.filter').forEach(input=>input.addEventListener('input',()=>{
const q=input.value.toLowerCase(), target=input.dataset.target;
let rows=[],items=[];
const direct=document.getElementById(target);
if(direct){rows=[...direct.querySelectorAll('tbody tr')];items=[...direct.querySelectorAll('.search-item')]}
else rows=[...document.querySelectorAll('.'+target+' tbody tr')];
rows.forEach(row=>row.classList.toggle('hide',!row.textContent.toLowerCase().includes(q)));
items.forEach(item=>item.classList.toggle('hide',!item.textContent.toLowerCase().includes(q)));
if(direct) direct.querySelectorAll('.search-group,.service-category,.path-category').forEach(group=>{
const visibleItems=[...group.querySelectorAll('.search-item')].some(item=>!item.classList.contains('hide'));
const visibleRows=[...group.querySelectorAll('tbody tr')].some(row=>!row.classList.contains('hide'));
group.classList.toggle('hide',!(visibleItems||visibleRows));
});
}));
document.querySelectorAll('nav a,.score-card').forEach(link=>link.addEventListener('click',()=>{
const target=document.querySelector(link.getAttribute('href'));
if(target&&target.tagName==='DETAILS')target.open=true;
}));
document.querySelectorAll('tbody').forEach(body=>{
if(!body.children.length){const tr=document.createElement('tr'),td=document.createElement('td');td.className='empty';td.colSpan=20;td.textContent='No evidence recorded for this section.';tr.appendChild(td);body.appendChild(tr)}
});
</script></body></html>