SAP security note 1568005, "Hard-coded credentials in SAP_BASIS". Below are the symptom and SAP recommended solution.
Description
Symptom
SAP_BASIS contains code that changes the program’s behaviour when a user is successfully authenticated with a certain username.
Solution
The correction consists of the removal of potentially exploitable coding. Please apply the attached correction instruction. The removal of the potentially exploitable coding is included in SAP_BASIS 710 SP13 and SAP_BASIS 711 SP08.
Reason and prerequisites
The program code contains a hard-coded username that changes the system’s behaviour if a user is successfully authenticated. The user may obtain additional information that should not be displayed.
Full note on SAP: SAP Support Launchpad note 1568005
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].



