SAP Security Note
Medium priority
SAP security note 1905286, "Hard-coded credentials in MDM-GDS", released on 25.02.2016. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
MDM-GDS contains code that changes the program’s behavior when a user is successfully authenticated with a certain user name.
Solution
Implement the patch. Make sure that all the necessary application properties are set correctly and passwords are updated after deploying the correction.
Reason and prerequisites
The program code contains a hard-coded user name that changes the system’s behavior if a user is successfully authenticated. The user may obtain additional information that should not be displayed.
References
- 2271598 – SAP NetWeaver MDM GDS 2.0 SP04 Patch 23 Release Note
- 2271597 – SAP NetWeaver MDM GDS 2.1 SP03 Patch 56 Release Note
- 2270248 – SAP NetWeaver MDM GDS 2.1 SP04 Patch 7 Release Note
Affected components
- GDSCORE: Versions 2.0 and 2.1
- MDM_CONT_GDS: Versions 2.0 and 2.1
Full note on SAP: SAP Support Launchpad note 1905286
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
