SAP security note 2114025, "Hard-coded credentials in SAP Content Server", is released on August 11, 2015. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP Content Server contains code that alters the program’s behavior when a user is successfully authenticated with certain usernames. An attacker can authenticate to SAP Content Server without legitimate credentials or escalate privileges. This vulnerability is due to hard-coded usernames and passwords in the program’s source code, allowing unauthorized access.
Solution
To mitigate this vulnerability, perform the following manual activities:
- Refer to SAP Note 514500 and update to the latest patch of SAP Content Server 6.50.
- After updating, delete the *.certs and *.pse files from the security directory (PSEDir) at the OS level. The PSEDir path can be found in the cs.conf file.
- Regenerate the certificates at the repository level via CSADMIN.
References
Affected components
- CONTSERV: Version 6.50
Full note on SAP: SAP Support Launchpad note 2114025
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



