SAP Security Note
High priority
SAP security note 1586739, "Hard-coded credentials in FI-FM", is released on 12.07.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
FI-FM contains code that alters the system’s behavior when a user is successfully authenticated with a specific username. This hard-coded credential can lead to unauthorized access, allowing users to obtain additional information that should remain restricted.
Solution
Implement the advance corrections provided in this security note to remove the hard-coded credentials and secure the authentication process within the FI-FM module.
Reason and prerequisites
The presence of hard-coded credentials poses a significant security risk. Unauthorized users could exploit this vulnerability to gain elevated access within the FI-FM module, potentially leading to data breaches and manipulation of financial information.
Affected components
- SAP_APPL 470
- SAP_APPL 500
- SAP_APPL 600
- SAP_APPL 602
- SAP_APPL 603
- SAP_APPL 604
- SAP_APPL 605
Full note on SAP: SAP Support Launchpad note 1586739
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



