Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
Производитель ПО
Наименование ПО
SAP Notes
(1724604-2)
Описание
A default key phrase is set for the secure store by the Java upgrade tool (SAPJup) when upgrading an SAP system from a source release based on SAP NetWeaver 2004 or on SAP NetWeaver 7.0 to a target release based on SAP NetWeaver PI 7.10 or on SAP NetWeaver 7.3 (switch-based upgrade).
A dialog must be displayed by the upgrade tool that prompts the user to replace the default secure store key phrase with a new one, but due to a bug in the upgrade tool, this dialog is not displayed. As a result, the systems that are upgraded with the older version of the upgrade tool without the new key phrase dialog, still have the default key phrase set on the secure store.
A dialog must be displayed by the upgrade tool that prompts the user to replace the default secure store key phrase with a new one, but due to a bug in the upgrade tool, this dialog is not displayed. As a result, the systems that are upgraded with the older version of the upgrade tool without the new key phrase dialog, still have the default key phrase set on the secure store.
Как исправить
Change the secure store key phrase according to SAP Note 1683616 if the system is upgraded with SAPJup tool version with a patch level lower than PL 54.
Ссылки