Skip links
SAP BTP · CAP Extensions

Security Scan for Your SAP CAP Extensions

Clean core moves custom logic to BTP. We scan it - with SAP context.

As custom code leaves the ABAP stack for CAP side-by-side extensions, a new risk surface arrives: CDS service exposure, authorization annotations, Node.js/Java injection and xsuaa config. ABAP tools do not understand it and generic SAST does not understand it in SAP context. RedRays scans the whole project in one pass - CDS, handlers and the security descriptor together - and returns findings with the exact file and line.

Get a free scan See what it finds
CDS · Node · Javawhole project, one pass
Authorization-firstevery service, entity, action
Same console as ABAPone findings model

Why CAP needs its own scan

New surface

A different risk model

A CAP app is CDS models plus Node.js/Java handlers plus config (xs-security.json, mta.yaml) - authorization annotations, service exposure and injection. Not ABAP.

Open by default

Silent over-exposure

A CDS entity or action exposed in a service with no @requires or @restrict is reachable by default - the classic CAP mistake.

Cross-file

Read together

Real posture is defined by the service, its handler and the security descriptor combined, so RedRays correlates them - not one file at a time.

One platform

Not a second tool

CAP findings flow through the same console, findings model and reports as your ABAP and CPI scans.

What RedRays finds in CAP projects

Same platform and findings model as ABAP and CPI - each finding carries the exact file, line and offending source line.

Detect

Real bugs in your BTP app code

Reads the handlers, controllers and services in your CAP and BTP apps - tenant isolation gaps, information disclosure, missing CSRF protection, injection and broken authorization - each mapped to the exact file it lives in.

RedRays SAP CAP / BTP scan - findings including missing CSRF, information disclosure and tenant isolation
RedRays CAP finding detail with CVSS score, file, line and recommendation
Analyze

Every finding, explained and scored

Each finding carries a CVSS score, the exact file and line, a plain-language explanation and a concrete fix - here a state-changing POST with no CSRF token, down to the controller line - ready to triage, assign and export.

Connect

Connect Cloud Foundry, or upload a ZIP

Register a Cloud Foundry credential (a technical user with Space Developer) to browse your apps and scan their source, or upload a CAP project ZIP directly. The credential is encrypted at rest, per tenant.

RedRays Cloud Foundry apps view - browse apps or upload a CAP project ZIP

What it detects

CDS, Node.js/Java and configuration issues a CAP project ships with by default:

Missing authorizationSQL / CQL injectionCommand injectionPath traversalSSRFOver-broad xsuaa scopesWildcard redirect-urisHardcoded secretsMocked auth in production

Also on the platform

FAQ

What does the RedRays CAP scanner check?

It scans a whole SAP CAP project - CDS models, Node.js/Java handlers and config - for missing authorization, injection in handlers, path traversal, SSRF, over-broad xsuaa scopes, wildcard redirect-uris, hardcoded secrets and mocked auth left on in production, with the exact file and line.

How do I submit a CAP project?

Two ways: register a Cloud Foundry credential to browse and scan your apps' uploaded source, or upload a CAP project ZIP directly. Credentials are encrypted at rest and scoped per tenant.

What makes it SAP-aware, versus a generic scanner?

It does a mandatory authorization pass over every CDS service, entity and action, and correlates the service, its handler and the security descriptor together - the combination that defines real CAP posture, which generic SAST does not understand.

Is it a separate tool from the ABAP scanner?

No. CAP findings use the same console, findings model and PDF/Excel reports as your ABAP and CPI scans - one platform.

How do I try it?

Book a demo, or upload a CAP project for a free scan. Run it as SaaS or inside your own landscape.

See it on your own CAP project

Book a demo or upload a CAP project - we'll show you the findings, on your own code.