Research Library / Case Studies /

IT Services & Business Consulting

Global IT Services Consultancy Conducts Web Application Assessment On 12 Apps

One of India's largest IT services companies had Payatu test its central ERP system's 12 mission-critical applications within a tight six-month window. The assessment uncovered 120 vulnerabilities and delivered an application-by-application remediation path.
Web Application Security Assessment

At a glance

INDUSTRY

IT Services & Business Consulting

CLIENT PROFILE

One of India's largest multinational IT services, consulting and business solutions providers

SERVICES

Web Application Security Assessment

ENGAGEMENT

6-month web application assessment of 12 applications under one central ERP system

key Numbers

12

Applications Assessed

120

Vulnerabilities Identified Across the Suite

Key Takeaways

  • Client – One of India's largest multinational IT services, consulting and business solutions providers.

  • Problem – The client's central ERP system, automating over 10 business functions across 12 mission-critical applications, needed a full security assessment within a compressed six-month window.

  • Assessed all 12 applications individually, redesigned the testing process to meet the client’s timeline, and identified vulnerabilities including missing authentication, insecure direct object references, and privilege escalation.

the challenge

Why the client called us in

One of India's largest multinational IT consultancies runs its entire business, accounting, project management, sales and more, through a single central ERP system serving a workforce in the hundreds of thousands. Payatu was brought in to pressure-test the 12 mission-critical applications behind that system, on a brutal timeline: all 12 tested in 3 months, every fix verified in the 3 months after.

  • Identify vulnerabilities that could grant access to internal networks
  • Find issues that would let an attacker copy or access sensitive data
  • Confirm whether existing security controls could actually be bypassed

‍
‍

‍

scope of engagement

What was in scope

  1. Application suite enabling the client's financial activities, implementations, enhancements and production support
  2. Application suite automating lender-related financial activities for the client and its subsidiaries
  3. Project management system tracking employees' work time for payroll
  4. Contacts application for scheduling meetings and sharing stakeholder and resource information
  5. Accounts application used by business units to maintain global customer accounts, linked to external data providers such as D&B
  6. Access management application controlling user access to functionality across the parent system
  7. Offerings application for creating and routing new offerings for approval
  8. Opportunities application for managing opportunities, timelines, contracts and offerings
  9. Project resource management application for allocating resources to projects
  10. Project commercial management application for managing customer contracts and project assignment
  11. Work management application for allocating work to employees
  12. Contract management system serving as the enterprise repository for signed contracts and their lifecycle

Our Approach

How Payatu ran the engagement

01

Scoping and Access Coordination
Payatu mapped the parent ERP system's 12 constituent applications and coordinated access to each one, working around a multi- account structure and staggered application handovers.

02

Application-by-Application Assessment
Each of the 12 applications was assessed individually for vulnerabilities that could grant access to internal networks, expose data, or bypass implemented security controls, within an overall 3- month testing window.

03

Process Redesign for Timely Delivery
Because receiving and assessing applications one at a time proved slow, Payatu redesigned its process flow mid-engagement to keep pace with the client's 6-month deadline for testing and remediation.

04

Reporting and Retest
Findings were compiled per application with High, Medium and Low severity ratings, and retesting was carried out as the client fixed vulnerabilities, despite recurring timeline shifts and internal coordination gaps on the client's side.

Key findings

What we found

HIGH
Missing Authentication
Several applications lacked authentication and authorization checks on server-side endpoints, allowing functions to be reached without valid credentials.
HIGH
Insecure Direct Object Reference
Objects were mapped directly to sequential IDs rather than hashed references, allowing unauthorized access to other users' data by manipulating identifiers.
HIGH
Privilege Escalation
Weak server-side authorization checks allowed users to escalate privileges beyond their intended access level.

the outcome

Results and Impact

Payatu's assessment gave the client an honest picture of its actual security posture across a system it depends on to run core business functions. With 120 vulnerabilities identified and mapped by application and severity, the client's team could fix critical bugs with clear priorities instead of guesswork.

‍

  • Assessed all 12 applications under the client's central ERP system within the agreed six-month window

  • Identified 120 vulnerabilities, spanning missing authentication, insecure direct object reference, privilege escalation and formula injection

  • Delivered application-by-application remediation guidance, down to specific server-side authorization fixes

  • Helped the client fix critical bugs and close the gap between assumed and actual security posture

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment