SAP Security Note
Medium priority
SAP security note 1415547, "Security corrections ST-SER 2008.2", released on March 26, 2010. Below are the symptom and SAP recommended solution.
Description
Symptom
Various sections of source code contain hard-coded user names intended for SAP-internal testing purposes. Although unlikely to affect production systems, this practice bypasses roles and the authorization concept, posing a security risk.
Risk: Hard-coded user names can circumvent the authorization framework, potentially leading to unauthorized access.
Solution
To address the issue, you can either:
- Import Support Package 7 for ST-SER 2008.2
- Implement the correction instructions for Support Package 6
Reason and prerequisites
- Correction of security-relevant source code.
- Removal of user-specific test source code.
- Evaluation: low probability of misuse primarily by SAP services; low impact potential.
References
Full note on SAP: SAP Support Launchpad note 1415547
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




