Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Hard-coded credentials in RHIQREG0 and HRPIQ00PLVAR, SAP security note 1491631

SAP Note 1491631
SAP Security Note
High priority

SAP security note 1491631, “Hard-coded credentials in RHIQREG0 and HRPIQ00PLVAR”, was released on October 12, 2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentIS-HER-CM-AD (Industry-Specific Components > Higher Education and Research > Student Lifecycle Management > Administration)
PriorityHigh priority
TypeSAP Security Note
Version4
StatusReleased for Customer
Released onOctober 12, 2010

Description

Symptom

The Report Program RHIQREG0 and the Function Group HRPIQ00PLVAR contain hard-coded credentials that alter the program’s behavior when a user successfully authenticates with a specific username.

Solution

Apply SAP Note 1491631 to correct the issue.

Reason and prerequisites

The program code includes a hard-coded username that changes the system’s behavior upon successful user authentication. This vulnerability allows a user to obtain additional information that should not be accessible.

Affected components

  • IS-PS-CA 472
  • IS-PS-CA 600
  • IS-PS-CA 602
  • IS-PS-CA 603
  • IS-PS-CA 604
  • IS-PS-CA 605

Full note on SAP: SAP Support Launchpad note 1491631

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More