SAP security note 1333668, "Security Checks: Model Mix Planning", is a note. Below are the symptom, SAP recommended solution, reason and prerequisites and the affected software components.
Description
Symptom
There are backdoors/undocumented personal test hacks used by the developer in their programs. Developers have hard-coded their usernames in the program.
Solution
Implement the correction instructions.
This security note addresses the presence of unauthorized backdoors and hard-coded usernames within the Model Mix Planning component of the SAP Supply Chain Management suite. The issue stems from program errors introduced by developers during the creation of the application. To mitigate this security risk, apply the provided correction instructions.
Reason and prerequisites
Program Error
References
Affected components
- Supply Chain Management > Advanced Planning and Optimization > Production Planning and Detailed Scheduling > Model Mix Planning (SCM-APO-PPS-MMP) – SCM 410, 500, 510, 700
Full note on SAP: SAP Support Launchpad note 1333668
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
