SAP Security Note
Low priority
SAP security note 1503843, "Hard-coded credentials in BSP page", is a note released on 12.10.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A hard-coded username contains code which changes the program’s behavior when a user successfully authenticates with a certain username.
Solution
Implement the attached correction instructions or import the relevant Support Package.
Reason and prerequisites
The program code contains a hard-coded username which changes the system’s behavior should a user authenticate successfully. The user may obtain additional information which should not be displayed.
Affected components
- ERECRUIT: 300, 600, 603, 604, 605
Full note on SAP: SAP Support Launchpad note 1503843
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
