Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Hard-coded credentials in BSP page, SAP security note 1503843

SAP Note 1503843
SAP Security Note
Low priority

SAP security note 1503843, "Hard-coded credentials in BSP page", is a note released on 12.10.2010. Below are the symptom, SAP recommended solution and the affected software components.

ComponentPersonnel Management > E-Recruiting (PA-ER)
PriorityCorrection with low priority
TypeSAP Security Note
StatusReleased for Customer
Released on12.10.2010

Description

Symptom

A hard-coded username contains code which changes the program’s behavior when a user successfully authenticates with a certain username.

Solution

Implement the attached correction instructions or import the relevant Support Package.

Reason and prerequisites

The program code contains a hard-coded username which changes the system’s behavior should a user authenticate successfully. The user may obtain additional information which should not be displayed.

Affected components

  • ERECRUIT: 300, 600, 603, 604, 605

Full note on SAP: SAP Support Launchpad note 1503843

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More