Onapsis Bizploit is a penetration testing framework for SAP aimed at assisting security experts in the discovery, exploration, vulnerability assessment, and exploitation phases of a specialized SAP security assessment.
The framework currently comes with several plugins for assessing the security of SAP Business platforms. Additional plugins are available for broader platform support including Oracle.
Today, most organizations using SAP are expanding beyond simply defining SAP roles and profiles. They have integrated the technical layer of their SAP platform into regular assessment processes in order to address the growing threat of cyberattacks on their business-critical systems.
With Bizploit, you can perform basic analysis of some of the existing technical vulnerabilities affecting SAP systems, which often pose critical risks to the integrity of the entire platform.
New features of v1.50
- New exploits for the Management Console.
- New modules for SAProuter.
- New modules for remote execution of RFC functions.
- Module for detecting the CTC Verb Tampering vulnerability.
- Many bug fixes.

