SAP security note 1578067, “Hard-coded credentials in CA-GTF-RCM”, is a note. Below are the symptom, SAP recommended solution, references and the affected software components.
Description
Symptom
CA-GTF-RCM contains code which changes the program’s behaviour when a user successfully authenticates with a certain username. A malicious user can authenticate to CA-GTF-RCM without legitimate own credentials or potentially escalate privileges.
Solution
Apply this note.
Reason and prerequisites
The program code contains a hard-coded username which changes the system’s behaviour should a user authenticate successfully. The user may obtain additional information which should not be displayed.
The vulnerability is caused by a hard-coded username-password combination in the program’s source code. A malicious user who specifies these credentials can log into the system without having been assigned legitimate access by the system administrator(s). In case a user already has privileges to log in with, an Escalation of Privileges may be possible if the hard-coded account has higher access rights than the original user.
References
Affected components
- SAP_ABA 702
- SAP_ABA 710
- SAP_ABA 711
- SAP_ABA 720
- SAP_ABA 730
Full note on SAP: SAP Support Launchpad note 1578067
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
