Application Development Discussions
Join the discussions or start your own on all things application development, including tools and APIs, programming models, and keeping your skills sharp.
cancel
Showing results for 
Search instead for 
Did you mean: 

security-based code validation products?

JR_LM
Explorer
0 Kudos

My company is planning on using third-party ABAP development services and because if this, a concern has been raised about the risk of malicious code being inserted into delivered code.

The question has been raised -- Is there a product that can scan ABAP code looking for known vulnerabilities? Any pointers or suggestions are appreciated.

Thanks in advance.

2 REPLIES 2

Former Member
0 Kudos

Hi Joseph,

Interesting question - I don't recall seeing anything on the market for this, though maybe someone in the ABAP forum may have a better idea.

A previous client in a similar situation went through code review to try and catch obvious stuff but that's not exactly infallible.

Good luck in finding a solution & let us know if you find anything.

Cheers

Alex

JimSpath
Active Contributor
0 Kudos

I've answered the same question on the asug.com site.

If you're an ASUG member, you can read the thread here:

http://www.asug.com/DiscussionForums/DiscussionForums/tabid/312/view/topic/postid/82753/ptarget/8275...

Briefly, perhaps try transaction SCI.

Jim