Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Hard-coded credentials in CRM-ISA, SAP security note 1602143

SAP Note 1602143

SAP security note 1602143, "Hard-coded credentials in CRM-ISA", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An attacker can be authenticated to CRM-ISA without having their own legitimate credentials, or they may escalate privileges.

Solution

This note contains Java correction(s) for E-Commerce and Web Channel.

  • For more information about applying Java patches, refer to Note 877887.
  • See Note 1546959 for information about the patch strategy.

Reason and prerequisites

The vulnerability is caused by a hard-coded username and password combination in the program’s source code. An attacker who specifies these credentials can log on to the system without having been assigned legitimate access by the system administrator(s). If a user already has privileges with which they can log on, an escalation of privileges may be possible if the hard-coded account has higher access rights than the original user.

References

Affected components

  • SAP-CRMISA 4.0_640
  • SAP-CRMJAV 5.0
  • SAP-CRMJAV 6.0
  • SAP-CRMJAV 700
  • SAP-CRMJAV 701
  • SAP-CRMJAV 730
  • SAP-CRMWEB 5.0
  • SAP-CRMWEB 6.0
  • SAP-CRMWEB 700
  • SAP-CRMWEB 701
  • SAP-CRMWEB 730
  • SAP-SHRWEB 5.0
  • SAP-SHRWEB 6.0
  • SAP-SHRWEB 700
  • SAP-SHRWEB 701
  • SAP-SHRWEB 730
  • SAP-SHRJAV 5.0
  • SAP-SHRJAV 6.0
  • SAP-SHRJAV 700
  • SAP-SHRJAV 701
  • SAP-SHRJAV 730
  • SAP-CRMAPP 5.0
  • SAP-CRMAPP 6.0
  • SAP-CRMAPP 700
  • SAP-CRMAPP 701
  • SAP-CRMAPP 730
  • SAP-SHRAPP 5.0
  • SAP-SHRAPP 6.0
  • SAP-SHRAPP 700
  • SAP-SHRAPP 701
  • SAP-SHRAPP 730

Full note on SAP: SAP Support Launchpad note 1602143

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More