High priority
SAP security note 1768068, "Hard-coded credentials in ABAP Class Builder", is a program error note released on November 13, 2012. Below are the symptom and SAP recommended solution.
Description
Symptom
ABAP Class Builder contains code that alters the program's behavior when a user is successfully authenticated with a specific username.
Solution
The backdoor vulnerability is removed starting with the support package specified in this note. It is recommended to:
- Apply the relevant support package listed below.
- Alternatively, apply the provided correction instructions.
Reason and prerequisites
The program code includes a hard-coded username that changes the system's behavior upon successful authentication. This vulnerability allows a user to obtain additional information that should remain hidden, potentially exposing sensitive data.
CVSS
Score 3.5 Vector: AV:N/AC:M/AU:S/C:N/I:P/A:N
References
Full note on SAP: SAP Support Launchpad note 1768068
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
