SAP Security Note
High priority
SAP security note 1486475, “Investigative Case Management Security Vulnerability”, is a program error note released on December 14, 2010. Below are the symptom and SAP recommended solution.
Description
Symptom
The program contains code that changes its behavior when a user successfully authenticates with a specific username. A malicious user can authenticate to Investigative Case Management (ICM) without legitimate credentials, potentially allowing privilege escalation.
Solution
Apply the corrective instructions associated with the installed release. For releases without a specified corrective instruction, no action is necessary.
Reason and prerequisites
The program code includes a hard-coded username that alters the system’s behavior upon successful authentication. This vulnerability may enable users to gain higher access rights than intended.
Full note on SAP: SAP Support Launchpad note 1486475
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
