SAP security note 1738965, "Hard-coded credentials in Open Hub", is a note. Below are the symptom, SAP recommended solution and affected software components.
Description
Symptom
BW-WHM-DBA-OHS contains code that changes the program’s behavior when a user is successfully authenticated with a certain user name.
Solution
SAP NetWeaver BW 7.30: Import Support Package 8 for SAP NetWeaver BW 7.30 (SAPKW73008) into your BW system. The Support Package is available when SAP Note 1680997 “SAPBWNews NW BW 7.30 BW ABAP SP8”, which describes this Support Package in more detail, is released for customers.
SAP NetWeaver BW 7.31 (SAP NW BW7.0 EnhP 3): Import Support Package 5 for SAP NetWeaver BW 7.31 (SAPKW73105) into your BW system. The Support Package is available when SAP Note 1708177 “SAPBWNews NW BW 7.31/7.03 ABAP SP5”, which describes this Support Package in more detail, is released for customers.
You can use the attached corrections as an advance correction. You must first read SAP Note 875986, which provides information about transaction SNOTE.
To provide information in advance, the SAP Notes mentioned above may already be available before the Support Package is released. In this case, the short text of the SAP Note contains the words “Preliminary version”.
Reason and prerequisites
The program code contains a hard-coded user name that changes the system’s behavior if a user is successfully authenticated. The user may obtain additional information that should not be displayed.
CVSS
Score 4.9 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:N
References
Affected components
- SAP_BW 730 to 730
- SAP_BW 731 to 731
Full note on SAP: SAP Support Launchpad note 1738965
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
