SAP Security Note
High priority
SAP security note 1491597, “Hard-coded credentials in FM HRIQ_INFTY_BUFFER_ACTIVATE”, is a program error note released on 12.10.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The Function Module HRIQ_INFTY_BUFFER_ACTIVATED contains hard-coded credentials which change the program’s behavior when a user successfully authenticates with a certain username.
Solution
Please apply the note for correction. You can download the SNOTE or view the PDF Version.
Reason and prerequisites
The program code contains a hard-coded username which alters the system’s behavior if a user authenticates successfully. This allows the user to obtain additional information that should not be displayed.
Affected components
- IS-PS-CA 472
- IS-PS-CA 600
- IS-PS-CA 602
- IS-PS-CA 603
- IS-PS-CA 604
- IS-PS-CA 605
Full note on SAP: SAP Support Launchpad note 1491597
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
