• Все разделы
  • Статьи
  • Медиа
  • Новости
  • Нормативные материалы
  • Конференции
  • Глоссарий

Не установлено обновление Note 1463009

Главная Специалистам База уязвимостей Не установлено обновление Note 1463009

Карточка уязвимости

Характеристики уязвимости

Уровень опасности
Оценка CVSS
Производитель ПО
SAP
Наименование ПО
SAP Notes (1463009-3) SAP Support Packages (SAPK-40019INCPRXRPM, SAPK-45010INCPRXRPM)
Описание
The program code contains a hard-coded username which changes the  system's behavior if a user authenticates successfully. The user may  obtain additional information which should not be displayed. This  vulnerability is caused by a hard-coded username-password combination in  the program's source code. A malicious user who specifies these credentials can log into the system without having been assigned  legitimate access by the system administrator(s). If a user already has  privileges to log in with, an Escalation of Privileges may be possible  if the hard-coded account has higher access rights than the original user.
Как исправить
Implement the source code changes given below.
Ссылки