Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Hard-coded credentials in CA-WUI-WST, SAP security note 1914777

SAP Note 1914777SAP Security NoteHigh priority

SAP security note 1914777, "Hard-coded credentials in CA-WUI-WST", is a program error note released on 11.02.2014. Below are the symptom, SAP recommended solution and affected software components.

ComponentCross-Application Components > WebClient User Interface > Web Services Tool (CA-WUI-WST)
CategoryProgram error
PriorityHigh priority
TypeSAP Security Note
Version3
StatusReleased for Customer
Released on11.02.2014
LanguageEnglish

Description

Symptom

CA-WUI-WST contains code that changes the program’s behavior when a user is successfully authenticated with a certain user name.

Solution

Apply attached correction instructions by implementing this note.

Reason and prerequisites

The program code contains a hard-coded user name that changes the system’s behavior if a user is successfully authenticated. The user may obtain additional information that should not be displayed.

CVSS

Score 3.5 Vector: AV:N/AC:M/AU:S/C:P/I:N/A:N

Affected components

  • WEBCUIF 701 to 701
  • WEBCUIF 731 to 731
  • WEBCUIF 746 to 746
  • WEBCUIF 747 to 747

Full note on SAP: SAP Support Launchpad note 1914777

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More