Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SAP’s FioriDAST is an internally developed system for dynamically scanning web applications while they run. As described by CSO Online on September 26, 2024, it combines simulated user interactions, browser-based testing, API fuzzing and the open-source Zed Attack Proxy (ZAP), with scans integrated into development pipelines. It is an in-house SAP project, not a publicly available SAP product.

What is FioriDAST?

FioriDAST is SAP’s dynamic application security testing (DAST) project for web applications. DAST examines an application as it runs, probing its behavior from the outside rather than analyzing only its source code. SAP developed the system because, according to the CSO Online account, it believed commercial dynamic scanners did not cover some of its concerns around sophisticated vulnerabilities, business logic and API security. That rationale is SAP’s account, not evidence that commercial scanners generally fail to find those issues; the same report says conventional scanners can be effective against common vulnerabilities such as SQL injection and cross-site scripting.

CSO Online reported that deployment began in July 2022. The system’s central idea is to automate more realistic application interactions so scanning can reach functionality and states that a simpler scan might miss.

How does the scanning process work?

1. A crawler imitates user actions

FioriDAST’s crawler is reported to imitate actions such as clicking links and filling in forms. Reaching different screens and application states can expose behavior that a scan would not examine if it never navigated to those parts of the application.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Browser execution tests client-side behavior

The system uses browser execution logic for client-side testing. This lets the scan exercise behavior that takes place in the browser, rather than treating the application solely as a collection of server responses.

3. API fuzzing and ZAP extend the checks

The reported approach also applies fuzz testing to APIs and integrates ZAP, an open-source security testing tool. Fuzz testing sends varied or unexpected inputs to check how an interface responds. The CSO Online report says FioriDAST checks API interactions, including whether authorization checks are applied consistently.

These are reported system mechanics, not results from an independent inspection or test of FioriDAST.

How does FioriDAST fit into development?

CSO Online says scans are integrated into continuous integration and continuous delivery (CI/CD) pipelines. In that model, security checks can run as part of the software delivery process, and findings can be routed back to development teams for remediation. The intent is to find and address issues during development rather than rely only on manual testing later in the release cycle.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This workflow depends on more than running a scanner: teams need to configure scans for their applications, interpret the results and resolve valid findings. The report says SAP was still working on configuration bugs and making issue reports clearer and more detailed.

What results did SAP report?

SAP Architect Expert Vladislav Dexheimer told CSO Online in 2024: “We can now scan 600 web applications per day within the SAP S/4HANA Cloud and in other SAP product areas.” This is a reported throughput figure from Dexheimer, not an independently audited benchmark or a head-to-head comparison with another scanner.

Dexheimer also said the project had saved “several thousand person-days” across the organization, with a considerable decrease in manual security testing and application time-to-market. The report gives no exact count or measurement period, so the savings should be understood as an approximate claim attributed to SAP. CSO Online also reported that SAP received a 2024 CSO Award for the project; that recognition is not a comparative performance measurement.

What were SAP’s stated next steps?

At the time of the September 2024 report, SAP was addressing configuration bugs, improving the clarity and detail of findings, and developing AI features for web crawling. The article also described expansion to SAP Business Technology Platform and SAP SuccessFactors as a plan. It does not confirm whether those plans were completed after publication.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How is FioriDAST different from static analysis?

Dynamic testing probes a running application; static analysis examines code without testing the application’s live behavior. SAP describes its separate Code Vulnerability Analyzer as a static code-scanning tool available in cloud and on-premise deployments. The cited SAP page supports that distinction; it does not identify Code Vulnerability Analyzer as part of FioriDAST.

These approaches address different parts of application security. A dynamic scan can exercise behavior in a running service, while static analysis can inspect code directly. The available reporting does not establish a complete SAP testing program or show how FioriDAST compares with particular commercial products.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What can be concluded from the public account?

The September 2024 CSO Online article describes a practical combination: simulate navigation and form use, execute client-side behavior in a browser, fuzz APIs, integrate ZAP and feed findings into development pipelines. It also reports SAP’s throughput and savings claims, but offers no named competitor, measured head-to-head evaluation or independently validated results. The account supports understanding FioriDAST’s reported design and intended workflow, not a conclusion that it outperforms other scanners.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.