SAP Security Note
Medium priority
SAP security note 1542645, "Users with Hardcoded Name & Password Created in BC-DOC-TER", is a program error note released on March 8, 2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
A malicious user can trick a user with elevated authorizations to run a report that creates users and RFC destinations with hardcoded usernames and passwords. This can potentially be used to exploit other vulnerabilities in the system.
Solution
To resolve the issue, implement the changes contained in the attached correction instructions in your system. This note corrects code that is only used internally by SAP and not in customer systems. No testing is required after applying the note.
Reason and prerequisites
The problem is caused by hardcoded usernames and passwords. The affected reports are protected by a special authorization object, allowing only users with elevated rights to run the report. These reports are usually not needed, so executing them would be unusual for a system administrator.
Affected components
- SAP_BASIS 620 to 640
- SAP_BASIS 700 to 702
- SAP_BASIS 710 to 730
- SAP_BASIS 72L to 800
Full note on SAP: SAP Support Launchpad note 1542645
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
