SAP security note 1582976, "Hard-coded User Name in RSRV_CCMS". Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
RSRV_CCMS contains code that alters the program’s behavior when a user successfully authenticates with a specific username. This hard-coded username change can grant unauthorized access to additional information that should remain restricted.
Solution
To resolve this security issue, apply the appropriate Support Package for your SAP NetWeaver BW version:
- SAP NetWeaver BW 7.00: Support Package SAPKW70027
- SAP NetWeaver BW 7.01 (Enhancement Package 1): Support Package SAPKW70110
- SAP NetWeaver BW 7.02 (Enhancement Package 2): Support Package SAPKW70209
- SAP NetWeaver BW 7.11: Support Package SAPKW71108
Affected components
- SAP Business Warehouse (SAP_BW): Versions 7.00 to 7.02, 7.10 to 7.11, 7.30 to 7.31
- SAP_BW_VIRTUAL_COMP: Version 7.01
Full note on SAP: SAP Support Launchpad note 1582976
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



