SAP security note 1458820, "The program contains Hardcoded username", is released on 09.11.2010. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The program contains hardcoded username and password credentials.
Solution
Implement the corrections attached.
Reason and prerequisites
The program code contains a hardcoded username which allows the user to bypass authorization and change the system behavior. This vulnerability is caused by a hard-coded username in the program’s source code.
CVSS
Score 0
References
Affected components
- Cross-Application Components > General Application Functions > People Centric UI Framework (CA-GTF-PCF)
- SAP_ABA: Versions 700 to 730
- BBPCRM: Version 400
Full note on SAP: SAP Support Launchpad note 1458820
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
