SAP security note 1315883, "RSUSR003: Standard passwords for hash code versions H and I", is a note. Below are the symptom, SAP recommended solution and reason and prerequisites.
Description
Symptom
You use the report RSUSR003 to obtain cross-client statements about the password status for the standard users SAP*, DDIC, SAPCPIC, and EARLYWATCH. However, the report does not support the new hash code versions H and I.
Solution
These corrections consist of an ABAP correction and a kernel correction.
- For Hash Code Version "I": To ensure that the system processes hash code version "I", you require only the ABAP corrections. Use the SAP Note Assistant to implement the correction instructions or import the relevant Support Package.
- For Hash Code Version "H": To ensure that the system can also process hash code version "H", a kernel correction is provided in addition to the ABAP correction. The lowest patch level of the kernel is specified in the "SP Patch Level" section.
Reason and prerequisites
The list of supported password hash value processes has been extended (see Note 991968).
References
- 1768995: CCDB: ConfigStore STANDARD_USERS
- 1414339: RSUSR003: Message "User ID Is Not a System User"
- 991968: List of values for "login/password_hash_algorithm"
- 968558: SUIM|RSUSR003 Missing functions
- 888889: Automatic checks for security notes using RSECNOTE (outdated)
Full note on SAP: SAP Support Launchpad note 1315883
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
