Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
Производитель ПО
Наименование ПО
SAP Notes
(1715079-3)
Описание
The vulnerability is caused by hard-coded user name and password combination in the program's database. An attacker who specifies these credentials can log on to the security providers of the Signature Service without having been assigned legitimate access by the system administrator(s). If a user already has privileges with which they can log on, an escalation of privileges may be possible if the hard-coded account has higher access rights than the original user.
Как исправить
The solution is implemented in the following version: Signature Service of SAP Billing Consolidation 2.0 SP5 AS or later.
Download this or any newer version from the SAP Service Marketplace and deploy it on your Java.Web AS. Follow the configuration instructions.
Download this or any newer version from the SAP Service Marketplace and deploy it on your Java.Web AS. Follow the configuration instructions.
Ссылки