SAP Security Note
High priority
SAP security note 1472807, "Hard-coded credentials in BRF", is a program error note released on 09.11.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The system contains code which changes the program’s behavior when a user successfully authenticates with a certain user name. Specifically, the runtime mode is switched to compiler mode when executing a BRF event.
Solution
Implement the correction instructions or import the relevant Support Package.
Reason and prerequisites
The program code includes a hard-coded username that alters the system’s behavior upon successful authentication. A user logs on to the system with this specific name.
CVSS
Score 0
References
This note refers to
Affected components
- SAP_BASIS: Versions 710 to 720
- SAP_ABA: Versions 700 to 702
Full note on SAP: SAP Support Launchpad note 1472807
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



