SAP security note 1768049, "Hard-coded credentials in XX-CSC-BR", is a security note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
Component XX-CSC-BR contains code that alters the program’s behavior when a user is successfully authenticated with a specific username. This can potentially allow unauthorized users to access additional information that should remain confidential.
Affected Coding: Example implementation of Badi J_1B_RANGE_NUMBER, method PRINT_CONFIGURATION.
Solution
Implement the relevant Support Package to address this vulnerability. For immediate correction, use the Note Assistant to apply the correction instructions provided in the support packages.
CVSS
Score 4.0 Vector: AV:N/AC:L/AU:S/C:P/I:N/A:N
Affected components
- SAP_APPL: 46C, 470, 500, 600, 602, 603, 604, 605, 606, 616
Full note on SAP: SAP Support Launchpad note 1768049
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
