Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Hard-coded credentials in EP-PCT-MGR-CO, SAP security note 1929473

SAP Note 1929473
High priority

SAP security note 1929473, "Hard-coded credentials in EP-PCT-MGR-CO", is a program error note released on 08.04.2014. Below are the symptom and SAP recommended solution.

ComponentEnterprise Portal > SAP Enterprise Portal Content > Manager functionality > BP for Manager Self-Service (FI) (EP-PCT-MGR-CO)
CategoryProgram error
PriorityHigh priority
StatusReleased for Customer
Released on08.04.2014

Description

Symptom

EP-PCT-MGR-CO contains a hard-coded username that changes the system's behavior upon successful authentication. This could allow a user to obtain additional information that should not be displayed.

Solution

Apply the attached correction instruction or update to the relevant Support Package for your release.

Reason and prerequisites

The program code contains a hard-coded username that modifies the system's behavior if a user is successfully authenticated. This may allow the user to access additional information that should remain restricted.

CVSS

Score 6.0 Vector: AV:N/AC:M/AU:S/C:P/I:P/A:P

Full note on SAP: SAP Support Launchpad note 1929473

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More