findings.jsonl. One row per confirmed surface, plus a summary.
Target
Put a domain on subfinder. The probe checks at most 200 bases.
How it works
subfinder lists hosts. httpx probes them. hac, backoffice, datahub, and identity each request one path. A datahub hit alone is not treated as SAP Commerce. The check does not sign in.
Overview
SAP Commerce administration consoles are not meant to sit on the public internet. This workflow enumerates hosts and requests HAC, Backoffice, and Data Hub paths. It keeps a hit only when the page matches Hybris or Data Hub markers. It does not submit a login. A confirmed console is an exposure finding for the commerce estate, separate from the published SAP NetWeaver path-traversal check. Point it at a domain you are authorised to test, and track the consoles in exposure management.
Pipeline
subfinder enumerates hosts for the domain you set.
hac, backoffice, datahub, and identity each request one path.
classify keeps a row only when HAC, Backoffice, or a Hybris header is present. A Data Hub path alone is not treated as SAP Commerce. The check does not sign in.
report writes findings.jsonl, one row per confirmed surface, plus a summary.
Inputs
Domain. Set on the subfinder node. Hosts come from that enumeration.
Outputs
findings.jsonl. One JSON line per confirmed Commerce surface, plus a summary.
Integrations
Subfinder. Host enumeration.
httpx. HTTP probe of the enumerated hosts.
Sample output
The line below is the summary from a completed run on brokencrystals.com on 2026-09-24. Fifty-seven hosts were probed. None were SAP Commerce.
kind
hosts_probed
sap_commerce
datahub_exposed
scanned_at
summary
57
0
0
2026-09-24T10:12:58Z
FAQ
Does this sign in to HAC?
No. It reads the public page and looks for Hybris administration markers.
Is this the NetWeaver check?
No. The published SAP NetWeaver workflow is a different product and a different bug.
How many hosts are checked?
At most 200 bases from the subfinder output.
Where should I run it?
On a domain you are authorised to test.
Related workflows
Exposed Database Scanner. Reach for this when the exposure is an open database port rather than a Commerce console.
Subdomain Takeover Scanner. Reach for this when the host name should not resolve, rather than when a console is mounted on it.