SAP learns to think.
We test whether it thinks securely.

SAP Joule, custom BTP agents, MCP servers and LLM pipelines create an entirely new attack surface. We test it offensively — before someone else does.

SAP AI attack surface 2026
User / Fiori Launchpad KNOWN
↓ Natural Language Prompt
SAP AI Agent (Joule / Custom) NEW SURFACE
↓ Tool Calls / Function Execution
MCP Server (Tool Access Layer) NEW SURFACE
↓ API Calls / RFC / OData
SAP Backend (S/4, BTP, ECC) KNOWN
↓ Data / transactions / postings
Business-critical data & processes IMPACT
⚠ Prompt → agent → MCP → SAP → posting: a chain no one tests

SAP agents act autonomously. But who checks their decisions?

Companies are rolling out SAP AI agents that independently create postings, trigger purchase orders and change data. No one is asking the security question.

The promise

“Just ask Joule for what you need.” SAP AI agents are meant to accelerate business processes: natural-language input, automatic tool selection, autonomous execution. A user types one sentence — the agent performs a posting.

The risk

The same chain that accelerates a legitimate process can be abused by an attacker: Prompt injection → agent acts in the user's context → MCP server executes an SAP transaction → the posting is done. No classic authorization concept applies.

What we test — and what no one else tests

SAP AI introduces three layers that appear in no classic SAP security assessment.

🤖

SAP AI Agents

Joule, custom BTP agents and AI-driven workflows that autonomously execute SAP transactions.

  • Prompt Injection (Direct & Indirect)
  • Agent Privilege Escalation
  • Tool Selection Manipulation
  • Context Window Poisoning
  • Multi-Step Chain Exploitation
  • Guardrail Bypass & Jailbreaking
🔗

MCP Server & Tool Layer

Model Context Protocol servers that act as a bridge between the AI model and the SAP backend.

  • MCP Tool Definition Manipulation
  • Unauthorized Tool Invocation
  • Input Schema Bypass
  • Credential Exposure in Tool Results
  • Cross-Tool Data Leakage
  • Server Impersonation & Spoofing

AI-to-SAP Pipeline

The entire chain: from the user prompt through LLM reasoning to the executed SAP transaction.

  • End-to-End Prompt-to-Transaction Attacks
  • RAG Poisoning (Knowledge Base Manipulation)
  • Embedding injection in vector databases
  • API Key & Token Leakage via LLM Output
  • Training Data Extraction
  • AI-Assisted Social Engineering

MCP Server Security for SAP

The Model Context Protocol is the new standard for tool integration in AI systems. In SAP environments, MCP servers become the bridge between agent and backend — and thus the most critical point of attack.

Why MCP servers are the new RFC connections

In the '90s, RFC connections linked SAP systems to one another — without anyone checking the security of those bridges. 30 years later we know the result: hundreds of invisible attack paths.

MCP servers repeat this pattern. They connect AI models to SAP backends, define which tools an agent may use, and execute actions in the user's context. Whoever controls the MCP server controls what the agent can do in SAP.

We audit MCP server implementations in SAP environments: tool definitions, authorization model, input validation, output sanitization and the entire trust chain from the user prompt to the SAP transaction.

Request an MCP security audit →
User / Fiori / Chat Interface
“Create a purchase order for €50,000 for vendor X”
↓ Natural Language
SAP AI Agent (Joule / Custom)
Reasoning · Tool Selection · Parameter Extraction · Multi-Step Planning
↓ MCP Protocol (Tool Call)
MCP Server (Tool Access Layer)
Tool: create_purchase_order · Input: {vendor: X, amount: 50000} · Auth: User Context
↓ OData / RFC / BAPI Call
SAP S/4HANA Backend
ME21N: purchase order created · posting executed · workflow started
⚠ Prompt Injection ⚠ Tool Confusion ⚠ Schema Bypass ⚠ Auth Escalation

Which SAP AI agents we test

From SAP's own agents to custom developments on BTP — every agent type has its own weaknesses.

SAP Native

SAP Joule

SAP's embedded AI copilot for S/4HANA, SuccessFactors, Ariba and BTP. Natural-language interaction with SAP transactions.

Attack vectors:
Indirect prompt injection via SAP data fields · Joule context manipulation · cross-module privilege abuse · guardrail bypass for protected transactions
Custom BTP

Custom AI agents on BTP

Custom-built agents on SAP BTP with CAP/RAP that access SAP backends via MCP servers.

Attack vectors:
Insecure MCP tool definitions · missing input validation · overprivileged service users · RAG poisoning via BTP Document Service
Integration

AI in SAP Integration Suite

AI-driven iFlows, intelligent routing and AI-generated transformations in the Integration Suite.

Attack vectors:
iFlow logic manipulation via AI · credential store access by the agent · message routing hijack · AI-generated mapping exploits
Third-Party

Third-party LLM integrations

OpenAI, Anthropic or open-source models connected to SAP systems via APIs.

Attack vectors:
API key exposure · data leakage to an external LLM · unencrypted prompts containing business data · model substitution attacks

Our AI security assessment process

Structured, reproducible and tailored to SAP-specific AI risks.

01

AI Landscape Mapping

Inventory of all AI components: agents, MCP servers, LLM connections, RAG pipelines, tool definitions.

02

Threat Modeling

SAP-specific AI threat model: which business processes are at risk from AI abuse?

03

Offensive Testing

Prompt injection, tool manipulation, MCP exploitation, end-to-end chain attacks on real systems.

04

Reporting & Hardening

Executive report + technical deep dive + concrete hardening measures for every vector found.

AI Security Assessments for SAP

Focused

MCP Server Audit

Targeted security audit of a single MCP server or AI agent implementation in SAP.

  • 1 MCP server or 1 agent
  • Tool definition review
  • Input/Output Validation Testing
  • Prompt injection attempts
  • Authorization model analysis
  • Technical report + quick wins
Recommended

Full AI Security Assessment

Complete assessment of all AI components in your SAP landscape: agents, MCP servers, pipelines.

  • All SAP AI agents & MCP servers
  • End-to-End Prompt-to-Transaction Testing
  • RAG Pipeline & Knowledge Base Audit
  • Cross-Agent Privilege Analysis
  • Executive report + board presentation
  • Hardening roadmap with priorities
Maximum

AI Red Team + SAP

Combination: AI security assessment + full SAP red team. Attack through the AI layer into the SAP backend and back.

  • AI agent as an attack vector for SAP
  • SAP compromise as an AI poisoning vector
  • Cross-Layer: AI + SAP + OT
  • Business impact validation
  • Full report + live demo
  • Remediation workshop (full day)

How secure are your SAP AI agents?

Most companies roll out SAP AI agents without asking the security question. We answer it — before an attacker does.

Get in touch →

30-minute intro call. Straight with the team that runs the tests.