What is SAP?
SAP (Systems, Applications and Products in Data Processing is a German company specialised in the development of business applications.
2. According to the information obtained from the first step, the PenTesters recognise database type, SAP version, and particular SAP modules. Finding the known vulnerabilities relevant to the target. Exploit the vulnerabilities to gain access.
3. Escalate Privileges to gain administrative access to control the whole SAP systems.Vulnerabilities in SAP xMII are particularly hazardous as it is a bridge between ERP (Enterprise Resource Planning), other enterprise applications and plant floor as well as OT (Operational Technology) devices. Any vulnerability affecting SAP xMII may be utilised as an initial point of a multi-stage adversary targetting to control over plant devices and manufacturing systems.