SAP security note 1602051, "Hard-coded credentials in CRM-ISA", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
- Unauthorized access to CRM-ISA applications without valid credentials.
- Potential privilege escalation if the hard-coded account has higher access rights than the original user.
Solution
Apply the appropriate Support Package patch level attached to this note to address the vulnerability.
Reason and prerequisites
A vulnerability exists in CRM-ISA applications where an attacker can authenticate without legitimate credentials or escalate privileges. This issue arises from hard-coded usernames and passwords embedded in the program’s source code. If the hard-coded account possesses higher access rights, an attacker can leverage this to gain unauthorized access or elevate their privileges within the system.
CVSS
Score 0
References
- Note 1546959 – Patch strategies for SAP E-Commerce solutions
- Note 877887 – Installing Patches for CRM Java Components and FSCM BD
Affected components
- Customer Relationship Management > Internet Sales (SAP-CRMISA)
- CRM Java Components (SAP-CRMJAV)
- CRM Web Components (SAP-CRMWEB)
- SAP Shared Java Applications (SAP-SHRJAV)
- SAP Shared Web Components (SAP-SHRWEB)
- SAP CRM Applications (SAP-CRMAPP)
- SAP Shared Applications (SAP-SHRAPP)
Full note on SAP: SAP Support Launchpad note 1602051
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
