---
title: SAP CVA what is it?
description: Discover how SAP CVA ensures secure coding in SAP programs. Learn about the tools, activation process, security checks, and figures provided by SAP for code vulnerability analysis. Subscribe for weekly SAP Security insights.
image: https://www.aglea.com/hubfs/Aglea/Imported_Blog_Media/SAP%20CVA-Jun-14-2024-09-54-55-9999-AM.jpg
---

[linkedin](https://www.linkedin.com/company/292350?trk=vsrp_companies_res_name&trkInfo=VSRPsearchId%3A3373431891426179412478%2CVSRPtargetId%3A292350%2CVSRPcmpt%3Aprimary) [YouTube](https://www.youtube.com/c/AgleaSAPSecurity?sub_confirmation=1) [Twitter](https://twitter.com/AgleaItaly?lang=en)

[![Logo-Aglea-horsa-company](https://www.aglea.com/hubfs/Aglea/Aglea_November2018%20Theme/Images/Logo-Aglea-horsa-company.webp) ](https://www.aglea.com/en)

# SAP CVA what is it?

# SAP CVA what is it?

Posted by [Klea Duro](https://www.aglea.com/en/blog/author/klea-duro) on Oct 18, 2024 8:15:00 AM

- [Tweet](https://twitter.com/share)

What can be done to check whether programs developed in SAP comply with security standards?

![SAP CVA](https://www.aglea.com/hs-fs/hubfs/Aglea/Imported_Blog_Media/SAP%20CVA-Jun-14-2024-09-54-55-9999-AM.jpg?width=528&height=1152&name=SAP%20CVA-Jun-14-2024-09-54-55-9999-AM.jpg)

What tools does SAP offer out-of-the-box for secure programming?

 

## Are there already tools included in the SAP suite?

Yes, there are several tools you can use that are already present in [SAP S/4HANA](https://www.aglea.com/en/sap-security-hana) (some already in the ECC suite)

- **ABAP Test Cockpit (ATC transaction)** is the main framework for performing checks on custom developments 
    - **Code Inspector (SCI transaction)**. It allows to perform checks related to: performance, security (some basic checks), syntax. In this case it should be used for checks during development and in routine maintenance
    - **Extended Program Check (SLIN transaction)**. Allows you to perform checks that would normally take much longer if done in normal maintenance
    - **CVA Code Vulnerability analysis**.This is an add on that integrates into the existing tools in SAP. These are additional checks related to the safe development of code

 

![CVA Architettura](https://www.aglea.com/hs-fs/hubfs/Aglea/Imported_Blog_Media/CVA%20Architettura-Jun-14-2024-09-54-56-4546-AM.png?width=550&height=895&name=CVA%20Architettura-Jun-14-2024-09-54-56-4546-AM.png)

 

## How does it work and what is SAP Code Vulnerability Analysis?

- This is **an add on to be activated** **(subject to license)**
- Performs a static analysis of the custom code (i.e., all objects beginning with Z*, Y*, or /*)
- You can use it, once activated in the main SAP transactions already known to developers, e.g. SE38, SE80, SE24, se37 and so on but also from Eclipse
- It can be integrated into existing transport systems in SAP to perform code checking before releasing change requests

 

## How to activate it?

Through the RSLIN_SEC_LICENSE_SETUP report (or SLIN_ADMIN transaction) the Code Vulnerability Analysis add-on can be activated, attention. Activation of this add-on requires payment of a specific license, as mentioned above.

 

![CVA](https://www.aglea.com/hs-fs/hubfs/Aglea/Imported_Blog_Media/CVA-Jun-14-2024-09-54-55-6261-AM.png?width=539&height=605&name=CVA-Jun-14-2024-09-54-55-6261-AM.png)

 

You can also enable a feature to declare tables that contain critical and sensitive data so that they emerge during code testing.

 

## What security SAP checks are carried out?

This [SAP blog](https://community.sap.com/t5/application-development-blog-posts/code-vulnerability-analyzer-checks/ba-p/13339467) shows all the security checks that can be performed, among the main categories:

 

- SQL Injection
- ABAP Command Injections
- Call Injections
- Directory Traversal
- Insufficient authorization checks
- Potential back doors
- Possible attacks using Web technologies

 

Once triggered, it is possible to have the checks done directly by the developers on their own, or to also add checks as change requests are released. CVA checks can be triggered at that time.

 

![SAP CVA Change Request](https://www.aglea.com/hs-fs/hubfs/Aglea/Imported_Blog_Media/SAP%20CVA%20Change%20Request-Jun-14-2024-09-54-55-2246-AM.png?width=486&height=588&name=SAP%20CVA%20Change%20Request-Jun-14-2024-09-54-55-2246-AM.png)

 

## Check of non-SAP code?

In reality, SAP CVA allows only SAP code to be checked. But integration with Fortify software to checks other programming languages is planned and possible.

 

## What are the figures that SAP provides in code check?

There are basically 4 figures planned and suggested:

- Developer. Defines new programs or modifies existing ones, independently performs checks on the various domains, security, quality, robustness of the code
- Quality Manager. Identifies anomalies, plans check campaigns, defines possible "exclusions" or false positives
- ATC administrator, checks campaign logs and configures the tool

 

## What does Baseline mean in this context?

Through CVA, as in other code checking tools, it is possible to analyze a source code in a punctual manner or to analyze one's system or systems overall. In this case, a baseline can be generated, i.e., an initial massive analysis that later allows you to go in and decide how to act on the evidence that will be detected. Also introducing what are called exemptions in the tool.

 

 

Topics: [secure coding sap](https://www.aglea.com/blog/tag/secure-coding-sap), [sviluppo codice sicuro](https://www.aglea.com/blog/tag/sviluppo-codice-sicuro), [code vulnerability analysis](https://www.aglea.com/blog/tag/code-vulnerability-analysis), [sap cva](https://www.aglea.com/blog/tag/sap-cva), [sap developer](https://www.aglea.com/blog/tag/sap-developer)

 Topics: [Secure programming](https://www.aglea.com/en/blog/tag/secure-programming)

### Subscribe Here!

### Blog Aglea, cosa puoi trovare?

Ogni mercoledì pubblichiamo articoli, interviste e documenti relativi alla security SAP.

Cosa puoi trovare:

- Suggerimenti su come mettere in sicurezza i sistemi SAP
- Come fare a … (How To)
- Checklist
- Gli errori comuni che spesso vengono fatti in ambito Security SAP
- Interviste con esperti del settore
- Chi è AGLEA quale è la nostra vision security SAP

### Recent Posts

### Post By Topic

- [SAP Security (12)](https://www.aglea.com/en/blog/tag/sap-security)
- [SAP GRC (11)](https://www.aglea.com/en/blog/tag/sap-grc)
- [pfcg (8)](https://www.aglea.com/en/blog/tag/pfcg)
- [gdpr (7)](https://www.aglea.com/en/blog/tag/gdpr)
- [SAP GDPR (5)](https://www.aglea.com/en/blog/tag/sap-gdpr)
- [Segregation of duties (5)](https://www.aglea.com/en/blog/tag/segregation-of-duties)
- [governance (5)](https://www.aglea.com/en/blog/tag/governance)
- [sod (5)](https://www.aglea.com/en/blog/tag/sod)
- [SAP ECC (4)](https://www.aglea.com/en/blog/tag/sap-ecc)
- [audit sap (4)](https://www.aglea.com/en/blog/tag/audit-sap)
- [auditing (4)](https://www.aglea.com/en/blog/tag/auditing)
- [sap consulenza security (4)](https://www.aglea.com/en/blog/tag/sap-consulenza-security)
- [sap password (4)](https://www.aglea.com/en/blog/tag/sap-password)
- [HANA (3)](https://www.aglea.com/en/blog/tag/hana)
- [SAP HR (3)](https://www.aglea.com/en/blog/tag/sap-hr)
- [UI logging (3)](https://www.aglea.com/en/blog/tag/ui-logging)
- [rfc security (3)](https://www.aglea.com/en/blog/tag/rfc-security)
- [sap cyber security (3)](https://www.aglea.com/en/blog/tag/sap-cyber-security)
- [sap hana (3)](https://www.aglea.com/en/blog/tag/sap-hana)
- [sap_all (3)](https://www.aglea.com/en/blog/tag/sap_all)
- [security audit log (3)](https://www.aglea.com/en/blog/tag/security-audit-log)
- [sicurezza sap (3)](https://www.aglea.com/en/blog/tag/sicurezza-sap)
- [su53 (3)](https://www.aglea.com/en/blog/tag/su53)
- [HANA Security (2)](https://www.aglea.com/en/blog/tag/hana-security)
- [ISO (2)](https://www.aglea.com/en/blog/tag/iso)
- [Profiles (2)](https://www.aglea.com/en/blog/tag/profiles)
- [SAP FIORI Security (2)](https://www.aglea.com/en/blog/tag/sap-fiori-security)
- [SAP audit (2)](https://www.aglea.com/en/blog/tag/sap-audit)
- [Secure programming (2)](https://www.aglea.com/en/blog/tag/secure-programming)
- [UCON (2)](https://www.aglea.com/en/blog/tag/ucon)
- [UI Masking (2)](https://www.aglea.com/en/blog/tag/ui-masking)
- [access management (2)](https://www.aglea.com/en/blog/tag/access-management)
- [authorization concept (2)](https://www.aglea.com/en/blog/tag/authorization-concept)
- [autorizzazioni sap (2)](https://www.aglea.com/en/blog/tag/autorizzazioni-sap)
- [consulenti (2)](https://www.aglea.com/en/blog/tag/consulenti)
- [corso (2)](https://www.aglea.com/en/blog/tag/corso)
- [e-learning (2)](https://www.aglea.com/en/blog/tag/e-learning)
- [password policy (2)](https://www.aglea.com/en/blog/tag/password-policy)
- [patch (2)](https://www.aglea.com/en/blog/tag/patch)
- [programmazione sicura (2)](https://www.aglea.com/en/blog/tag/programmazione-sicura)
- [quality (2)](https://www.aglea.com/en/blog/tag/quality)
- [rfc (2)](https://www.aglea.com/en/blog/tag/rfc)
- [ruoli (2)](https://www.aglea.com/en/blog/tag/ruoli)
- [sap access control (2)](https://www.aglea.com/en/blog/tag/sap-access-control)
- [sap custom (2)](https://www.aglea.com/en/blog/tag/sap-custom)
- [sap etd (2)](https://www.aglea.com/en/blog/tag/sap-etd)
- [sap gui (2)](https://www.aglea.com/en/blog/tag/sap-gui)
- [sap query (2)](https://www.aglea.com/en/blog/tag/sap-query)
- [sap security guidelines (2)](https://www.aglea.com/en/blog/tag/sap-security-guidelines)
- [sap siem (2)](https://www.aglea.com/en/blog/tag/sap-siem)
- [sap standard role (2)](https://www.aglea.com/en/blog/tag/sap-standard-role)
- [sap super user (2)](https://www.aglea.com/en/blog/tag/sap-super-user)
- [sap vulnerability (2)](https://www.aglea.com/en/blog/tag/sap-vulnerability)
- [se16 (2)](https://www.aglea.com/en/blog/tag/se16)
- [security ams (2)](https://www.aglea.com/en/blog/tag/security-ams)
- [siem (2)](https://www.aglea.com/en/blog/tag/siem)
- [soar (2)](https://www.aglea.com/en/blog/tag/soar)
- [supporto sap ams (2)](https://www.aglea.com/en/blog/tag/supporto-sap-ams)
- [test system (2)](https://www.aglea.com/en/blog/tag/test-system)
- [threat detection (2)](https://www.aglea.com/en/blog/tag/threat-detection)
- [upgrade (2)](https://www.aglea.com/en/blog/tag/upgrade)
- [312 (1)](https://www.aglea.com/en/blog/tag/312)
- [ABAP (1)](https://www.aglea.com/en/blog/tag/abap)
- [AI (1)](https://www.aglea.com/en/blog/tag/ai)
- [CVA (1)](https://www.aglea.com/en/blog/tag/cva)
- [DPO (1)](https://www.aglea.com/en/blog/tag/dpo)
- [FIORI Security (1)](https://www.aglea.com/en/blog/tag/fiori-security)
- [HANA Roles (1)](https://www.aglea.com/en/blog/tag/hana-roles)
- [PFCG SAP transaction (1)](https://www.aglea.com/en/blog/tag/pfcg-sap-transaction)
- [SAP Cloud Security (1)](https://www.aglea.com/en/blog/tag/sap-cloud-security)
- [SAP Consulting (1)](https://www.aglea.com/en/blog/tag/sap-consulting)
- [SAP DLP (1)](https://www.aglea.com/en/blog/tag/sap-dlp)
- [SAP Fraud Management (1)](https://www.aglea.com/en/blog/tag/sap-fraud-management)
- [SAP IDM (1)](https://www.aglea.com/en/blog/tag/sap-idm)
- [SAP LOG (1)](https://www.aglea.com/en/blog/tag/sap-log)
- [SAP Security Documentation (1)](https://www.aglea.com/en/blog/tag/sap-security-documentation)
- [SAP Table (1)](https://www.aglea.com/en/blog/tag/sap-table)
- [SAP Transactions (1)](https://www.aglea.com/en/blog/tag/sap-transactions)
- [SPOOL (1)](https://www.aglea.com/en/blog/tag/spool)
- [Security Analyzer (1)](https://www.aglea.com/en/blog/tag/security-analyzer)
- [Statistiche security SAP (1)](https://www.aglea.com/en/blog/tag/statistiche-security-sap)
- [Trace autorizzazioni SAP (1)](https://www.aglea.com/en/blog/tag/trace-autorizzazioni-sap)
- [User Access Management (1)](https://www.aglea.com/en/blog/tag/user-access-management)
- [aglea (1)](https://www.aglea.com/en/blog/tag/aglea)
- [audit (1)](https://www.aglea.com/en/blog/tag/audit)
- [authorization model (1)](https://www.aglea.com/en/blog/tag/authorization-model)
- [biometric (1)](https://www.aglea.com/en/blog/tag/biometric)
- [chatGPT (1)](https://www.aglea.com/en/blog/tag/chatgpt)
- [codice sicuro SAP (1)](https://www.aglea.com/en/blog/tag/codice-sicuro-sap)
- [consulenti sap security (1)](https://www.aglea.com/en/blog/tag/consulenti-sap-security)
- [consulenza sap security (1)](https://www.aglea.com/en/blog/tag/consulenza-sap-security)
- [crittografia SAP (1)](https://www.aglea.com/en/blog/tag/crittografia-sap)
- [custom transactions (1)](https://www.aglea.com/en/blog/tag/custom-transactions)
- [cyber security (1)](https://www.aglea.com/en/blog/tag/cyber-security)
- [data loss prevention (1)](https://www.aglea.com/en/blog/tag/data-loss-prevention)
- [data privacy (1)](https://www.aglea.com/en/blog/tag/data-privacy)
- [documentazione sap security (1)](https://www.aglea.com/en/blog/tag/documentazione-sap-security)
- [emergency users (1)](https://www.aglea.com/en/blog/tag/emergency-users)
- [gxp (1)](https://www.aglea.com/en/blog/tag/gxp)
- [identity management system (1)](https://www.aglea.com/en/blog/tag/identity-management-system)
- [idm (1)](https://www.aglea.com/en/blog/tag/idm)
- [log sap (1)](https://www.aglea.com/en/blog/tag/log-sap)
- [mail security sap (1)](https://www.aglea.com/en/blog/tag/mail-security-sap)
- [microsoft (1)](https://www.aglea.com/en/blog/tag/microsoft)
- [parameter sap (1)](https://www.aglea.com/en/blog/tag/parameter-sap)
- [processi security (1)](https://www.aglea.com/en/blog/tag/processi-security)
- [profili (1)](https://www.aglea.com/en/blog/tag/profili)
- [profili sap (1)](https://www.aglea.com/en/blog/tag/profili-sap)
- [progetti security sap (1)](https://www.aglea.com/en/blog/tag/progetti-security-sap)
- [quotazione borsa (1)](https://www.aglea.com/en/blog/tag/quotazione-borsa)
- [rfc destination (1)](https://www.aglea.com/en/blog/tag/rfc-destination)
- [role translation (1)](https://www.aglea.com/en/blog/tag/role-translation)
- [s_tabu_dis (1)](https://www.aglea.com/en/blog/tag/s_tabu_dis)
- [s_tabu_nam (1)](https://www.aglea.com/en/blog/tag/s_tabu_nam)
- [s_tabu_rfc (1)](https://www.aglea.com/en/blog/tag/s_tabu_rfc)
- [sap FIORI (1)](https://www.aglea.com/en/blog/tag/sap-fiori)
- [sap btp (1)](https://www.aglea.com/en/blog/tag/sap-btp)
- [sap data masking (1)](https://www.aglea.com/en/blog/tag/sap-data-masking)
- [sap dati personali (1)](https://www.aglea.com/en/blog/tag/sap-dati-personali)
- [sap developer (1)](https://www.aglea.com/en/blog/tag/sap-developer)
- [sap earlywatch (1)](https://www.aglea.com/en/blog/tag/sap-earlywatch)
- [sap grc 12 (1)](https://www.aglea.com/en/blog/tag/sap-grc-12)
- [sap grc tables (1)](https://www.aglea.com/en/blog/tag/sap-grc-tables)
- [sap gui history (1)](https://www.aglea.com/en/blog/tag/sap-gui-history)
- [sap gui security (1)](https://www.aglea.com/en/blog/tag/sap-gui-security)
- [sap gxp compliance (1)](https://www.aglea.com/en/blog/tag/sap-gxp-compliance)
- [sap ilm gdpr (1)](https://www.aglea.com/en/blog/tag/sap-ilm-gdpr)
- [sap license auditing (1)](https://www.aglea.com/en/blog/tag/sap-license-auditing)
- [sap logon (1)](https://www.aglea.com/en/blog/tag/sap-logon)
- [sap patch (1)](https://www.aglea.com/en/blog/tag/sap-patch)
- [sap security blog (1)](https://www.aglea.com/en/blog/tag/sap-security-blog)
- [sap security teal (1)](https://www.aglea.com/en/blog/tag/sap-security-teal)
- [sap sos (1)](https://www.aglea.com/en/blog/tag/sap-sos)
- [sap splunk (1)](https://www.aglea.com/en/blog/tag/sap-splunk)
- [sap sso (1)](https://www.aglea.com/en/blog/tag/sap-sso)
- [sap tabelle custom (1)](https://www.aglea.com/en/blog/tag/sap-tabelle-custom)
- [sap tdms (1)](https://www.aglea.com/en/blog/tag/sap-tdms)
- [sap_all_only_view (1)](https://www.aglea.com/en/blog/tag/sap_all_only_view)
- [se16n (1)](https://www.aglea.com/en/blog/tag/se16n)
- [secpol (1)](https://www.aglea.com/en/blog/tag/secpol)
- [secure coding sap (1)](https://www.aglea.com/en/blog/tag/secure-coding-sap)
- [secure operation map (1)](https://www.aglea.com/en/blog/tag/secure-operation-map)
- [security awareness (1)](https://www.aglea.com/en/blog/tag/security-awareness)
- [security bridge (1)](https://www.aglea.com/en/blog/tag/security-bridge)
- [sentinel (1)](https://www.aglea.com/en/blog/tag/sentinel)
- [sicurezza codice ABAP (1)](https://www.aglea.com/en/blog/tag/sicurezza-codice-abap)
- [sicurezza dei dati sap (1)](https://www.aglea.com/en/blog/tag/sicurezza-dei-dati-sap)
- [slaw (1)](https://www.aglea.com/en/blog/tag/slaw)
- [social engineering (1)](https://www.aglea.com/en/blog/tag/social-engineering)
- [sost (1)](https://www.aglea.com/en/blog/tag/sost)
- [sql (1)](https://www.aglea.com/en/blog/tag/sql)
- [su25 (1)](https://www.aglea.com/en/blog/tag/su25)
- [super utenti sap (1)](https://www.aglea.com/en/blog/tag/super-utenti-sap)
- [system users (1)](https://www.aglea.com/en/blog/tag/system-users)
- [tabelle (1)](https://www.aglea.com/en/blog/tag/tabelle)
- [tabelle SAP grc access control (1)](https://www.aglea.com/en/blog/tag/tabelle-sap-grc-access-control)
- [ticket management system (1)](https://www.aglea.com/en/blog/tag/ticket-management-system)
- [training (1)](https://www.aglea.com/en/blog/tag/training)
- [transazioni sap (1)](https://www.aglea.com/en/blog/tag/transazioni-sap)
- [userid (1)](https://www.aglea.com/en/blog/tag/userid)
- [usmm (1)](https://www.aglea.com/en/blog/tag/usmm)
- [ust04 (1)](https://www.aglea.com/en/blog/tag/ust04)
- [zero trust security (1)](https://www.aglea.com/en/blog/tag/zero-trust-security)

[See all](https://www.aglea.com/en/blog/sap-cva-what-is-it#)

## [SAP Security Blog AGLEA RSS Feed](https://www.aglea.com/blog/rss.xml)

Aglea s.r.l. P. IVA: IT 03868780960 - 2026  | Copy | [Note legali](https://cdn2.hubspot.net/hubfs/4422290/Aglea_November2018%20Theme/Pdfs/Privacy-policy-AGLEA.pdf)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Klea Duro",
    "url" : "https://www.aglea.com/en/blog/author/klea-duro"
  },
  "dateModified" : "2024-10-18T06:15:00.343Z",
  "datePublished" : "2024-10-18T06:15:00.000Z",
  "headline" : "SAP CVA what is it?",
  "image" : [ "https://www.aglea.com/hubfs/Aglea/Imported_Blog_Media/SAP%20CVA-Jun-14-2024-09-54-55-9999-AM.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.aglea.com/en/blog/sap-cva-what-is-it",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject"
    },
    "name" : "Horsa S.p.A."
  }
}
```