SAP Security Note
Medium priority
SAP security note 1518723, "hard coded credentials in ESFUtil code", is a program error note released on 12.04.2011. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
ESFUtil contains code that changes the program’s behaviour when a user is successfully authenticated with a certain username.
Solution
The hard-coded username, which was put in place for testing/debugging purposes, has been removed. The fix is available in NW 7.2L (ByD FP2.5) version. Apply the patch in this note to make the fix available.
Reason and prerequisites
The program code contains a hard-coded username that changes the system’s behaviour if a user is successfully authenticated. The user may obtain additional information that should not be displayed.
Affected components
- SAP_BASIS: From 72L to 800
Full note on SAP: SAP Support Launchpad note 1518723
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
