Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
Производитель ПО
Наименование ПО
SAP Notes
(1463009-3)
SAP Support Packages
(SAPK-40019INCPRXRPM, SAPK-45010INCPRXRPM)
Описание
The program code contains a hard-coded username which changes the system's behavior if a user authenticates successfully. The user may obtain additional information which should not be displayed. This vulnerability is caused by a hard-coded username-password combination in the program's source code. A malicious user who specifies these credentials can log into the system without having been assigned legitimate access by the system administrator(s). If a user already has privileges to log in with, an Escalation of Privileges may be possible if the hard-coded account has higher access rights than the original user.
Как исправить
Implement the source code changes given below.
Ссылки