Vendor URL: https://sap.com
Bug: Hard-coded Credentials
Reported: October 21, 2021
Date of Public Advisory: October 28, 2021
Reference: SAP Security Note 2971638
Author: Arpine Maghakyan (RedRays)
Title: Patch bypass for [CVE-2020-6369] Hard-coded Credentials in CA Introscope Enterprise Manager
Date published: 22.08.2022
Remotely Exploitable: Yes
Locally Exploitable: No
CVSS v3 Base Score: 7.5 / 10 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
CA Introscope Enterprise Manager’s releases 10.7.0.306 or lower, allow unauthenticated attackers to bypass the authentication if the administrator has not changed the default passwords for Admin and Guest. This may impact the confidentiality of the service.
The CA Introscope Enterprise Manager has the following configuration file with hardcoded usernames and hashed passwords.
In 2020, SAP Fixed hard-coded Credentials in CA Introscope Enterprise Manager, fixed passwords for Guest and Admin users, and forgot to remove the hardcoded passwords for cemadmin users.
We analyzed the hash and found the right password for the hash for the cemadmin user.
The main goal of RedRays is to narrow the security gap in both the technical and business realms. The company offers solutions to examine and protect SAP, Oracle, and Microsoft ERP systems against cyberattacks and internal fraud.
Typically, our customers are big organizations and managed service providers whose needs include the active monitoring and management of security across extensive SAP environments worldwide.
ABOUT RedRays R&D
The company’s competence is founded on RedRays’ research section, which specializes in vulnerability research and analysis of essential corporate applications. It has received several accolades from major software companies, including SAP, Oracle, Microsoft Dynamics, and IBM.
Experts from RedRays have been asked to lecture, present, and train at major international security conferences on all continents.
Address: Casablanca, Morocco