Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:30808
HistoryJun 14, 2014 - 12:00 a.m.

[Onapsis Security Advisories] Multiple Hard-coded Usernames in SAP Components

2014-06-1400:00:00
vulners.com
39

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Onapsis Security Advisories:Multiple Hard-coded Usernames (CWE-798) have
been found and patched in a variety of SAP components.
Summaries of the advisories with links to full versions follow:

  1. ONAPSIS-2014-011-SAP Project System Structures and Project-Oriented
    Procurement Hard-coded credentials
    =======================================================================
  • – Public Release Date: 2014-06-06

  • – Researcher: Sergio Abraham

  • – Initial Base CVSS v2: 6.0 (AV:N/AC:M/AU:S/C:P/I:P/A:P)

  • – Affected Components:

    • Project System
    • Structures
    • Project-Oriented Procurement
      (Check SAP Note 1791081 for detailed information on affected releases)
  • – Original Advisory:
    http://www.onapsis.com/resources/get.php?resid=adv_onapsis-2014-011

  1. ONAPSIS-2014-012-SAP Brazil Specific Add-On Hard-coded Credentials
    =====================================================================
  1. ONAPSIS-2014-013-SAP OIL Industry Solution Traders and Schedulers
    Workbench Hard-coded Credentials
    =====================================================================
  1. ONAPSIS-2014-014-SAP Upgrade tools for ABAP Hard-coded credentials
    =====================================================================
  1. ONAPSIS-2014-015-SAP Web Services Tool Hard-coded Credentials
    ================================================================
  1. ONAPSIS-2014-016-SAP CCMS Monitoring Hard-coded Credentials
    ==============================================================
  1. ONAPSIS-2014-017-SAP Transaction Data Pool Hard-coded Credentials
    ====================================================================
  1. ONAPSIS-2014-018-SAP Capacity Leveling Hard-coded Credentials
    ================================================================
  1. ONAPSIS-2014-019-SAP Open Hub Service Hard-coded Credentials
    ===============================================================

Ezequiel Gutesman
Director Of Research
Onapsis
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)
Comment: Onapsis Research Team

iEYEARECAAYFAlOSFqIACgkQz3i6WNVBcDU+6ACg6bPZdRxXlB/azq5CtxZKVxW0
ts0An3kslNviD8MfrDq6O/yxwvOa8yJ4
=SlbL
-----END PGP SIGNATURE-----