The landscape map in the RedRays Security Platform grades every path by the boundary it crosses, because an identical RFC destination with an identical stored credential is housekeeping between two development systems and is the finding a customer buys the product for when it runs from development into production.
A path has two ends and each end has a role in the landscape. Until both roles are known, the boundary cannot be graded, and a path with an ungraded boundary is still shown but is carrying less information than one with a graded boundary.
| Type | What it means on the map |
|---|---|
| Production | The system whose data and processes the controls exist to protect |
| Staging or pre-production | A system holding production-like data or feeding production directly |
| Quality | A system used for formal testing before transport into production |
| Test | A system used for functional testing |
| Development | A system where code and configuration originate, usually with the widest access |
| External | A host outside the SAP landscape, such as a cloud tenant or a partner endpoint |
| Router | An intermediate named in a route rather than an endpoint in its own right |
| Unknown | A host whose role has not been determined |
Two directions carry most of the weight, and they are different findings.
Upwards into production. A less controlled system holds a credential into a more controlled one. Whoever takes the development system takes production with it, and the change control, the approval process and the transport path that exist between those systems have all been bypassed by one configuration entry.
Downwards out of production. A production system holds a credential into a test or development system. This is often created for a refresh or a data feed and is treated as harmless because the target is unimportant. It is not harmless: it usually means production data can be pulled, and it gives an attacker inside production a quieter place to work.
A path between two systems of the same role is not a boundary crossing by this grading, and it is still worth reading. Two production systems that can each reach the other without a password mean that either of them falling costs both.
Because a system's role is a fact about your landscape, not a fact SAP publishes. The platform infers a type from the naming and addressing it can see, and naming conventions vary enough that inference is sometimes wrong or absent. An unknown end is treated as unknown rather than guessed at, and the boundary grade is withheld rather than invented, which is the same rule described in what a finding does and does not claim.
The practical consequence is worth stating plainly: set the types yourself for the systems that matter. A landscape whose production system is recorded as unknown produces a map that draws every path correctly and grades none of the crossings, and a manually set type is respected over any inference.
Type it by the data it holds rather than by its name. A system with production data in it is a production-grade target regardless of what the project called it, and typing it that way makes every path into it grade correctly.
No. Extra systems take the closest matching type, and the ordering is what the grading uses. The distinction that carries the finding is how far apart the two ends are and which way the arrow points.
It changes what the map can say, not what happens. A route naming an intermediate is drawn through that intermediate, so the far end appears as the route rather than as an environment with a role. Read the destination configuration to see which system is really at the end of it.
What one attack path says for the unit itself, RFC trust and stored credentials for the mechanism, and SAP threat modelling and attack paths for the overview.