SAP code is mostly written in ABAP, and it is an integral part of securing your SAP systems. ABAP developers often struggle to keep up with new and increasing changes and requirements in the fields of code security and code quality, leading to major vulnerabilities or misconfigurations within your SAP system. However, due to the average SAP system containing two million lines of custom-developed code, manual reviews are expensive, inefficient and time-consuming. As a result, custom code errors are frequent, and can heavily impact performance and lead to enormous financial costs. Download our ebook below to learn just how common these code issues are—based on analysis of the custom ABAP code of 373 Onapsis customer SAP systems—and explore the consequences they can have on overall system security, compliance, performance and stability.

About the Author
As CTO, JP leads the innovation team that keeps Onapsis on the cutting edge of the Business-Critical Application Security market, addressing some of the most complex problems that organizations are currently facing while managing and securing their ERP landscapes. JP helps manage the development of new products as well as support the ERP cybersecurity research efforts that have garnered critical acclaim for the Onapsis Research Labs. JP is regularly invited to speak and host trainings at global industry conferences, including Black Hat, HackInTheBox, AppSec, Troopers, Oracle OpenWorld and SAP TechEd, and is a founding member of the Cloud Security Alliance (CSA) Cloud ERP Working Group. Over his professional career, JP has led many Information Security consultancy projects for some of the world’s biggest companies around the globe in the fields of penetration and web application testing, vulnerability research, cybersecurity infosec auditing/standards, vulnerability research and more.
More about this author
Further Reading
The Truth About SAP Security Architecture: Why Embedded Tools Are a Single Point of Failure
Protecting enterprise core business processes requires resilient architecture. The latest data from the IBM Cost of a Data Breach Report shows the average global breach lifecycle stretches to 241 days. Organizations face severe financial penalties for slow threat containment. An architectural security failure stalls supply chains, disrupts financial closes, and brings operations to a complete…
Exploiting the Core: Inside the BTP and ABAP Security Vulnerabilities Weaponized by Attackers
As organizations aggressively adopt the SAP Business Technology Platform (BTP) to achieve a modern, agile architecture, the traditional security boundary around the enterprise resource planning (ERP) system is shifting. SAP drives the Clean Core strategy to move custom logic out of the core system. However, migrating custom applications to the cloud does not automatically eliminate…
What’s New in Q2 2026: More Data-Driven Insights, Expanded Landscape Visibility, and Intelligent Automation to Accelerate Response
At a Glance: Q2 2026 Release Highlights Securing complex ERP environments can be challenging, as it requires teams to maintain a proactive security posture that can outpace modern threat actors without creating unnecessary organizational gridlock that impedes business. As the only SAP® Endorsed App for cybersecurity, Onapsis is uniquely positioned to modernize business-critical application security…
