SAP security note 1602143, "Hard-coded credentials in CRM-ISA", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can be authenticated to CRM-ISA without having their own legitimate credentials, or they may escalate privileges.
Solution
This note contains Java correction(s) for E-Commerce and Web Channel.
- For more information about applying Java patches, refer to Note 877887.
- See Note 1546959 for information about the patch strategy.
Reason and prerequisites
The vulnerability is caused by a hard-coded username and password combination in the program’s source code. An attacker who specifies these credentials can log on to the system without having been assigned legitimate access by the system administrator(s). If a user already has privileges with which they can log on, an escalation of privileges may be possible if the hard-coded account has higher access rights than the original user.
References
This note refers to
Affected components
- SAP-CRMISA 4.0_640
- SAP-CRMJAV 5.0
- SAP-CRMJAV 6.0
- SAP-CRMJAV 700
- SAP-CRMJAV 701
- SAP-CRMJAV 730
- SAP-CRMWEB 5.0
- SAP-CRMWEB 6.0
- SAP-CRMWEB 700
- SAP-CRMWEB 701
- SAP-CRMWEB 730
- SAP-SHRWEB 5.0
- SAP-SHRWEB 6.0
- SAP-SHRWEB 700
- SAP-SHRWEB 701
- SAP-SHRWEB 730
- SAP-SHRJAV 5.0
- SAP-SHRJAV 6.0
- SAP-SHRJAV 700
- SAP-SHRJAV 701
- SAP-SHRJAV 730
- SAP-CRMAPP 5.0
- SAP-CRMAPP 6.0
- SAP-CRMAPP 700
- SAP-CRMAPP 701
- SAP-CRMAPP 730
- SAP-SHRAPP 5.0
- SAP-SHRAPP 6.0
- SAP-SHRAPP 700
- SAP-SHRAPP 701
- SAP-SHRAPP 730
Full note on SAP: SAP Support Launchpad note 1602143
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
