Sap fi Manager Self-Service hard-coded credential Security Restriction Bypass Vulnerability
Release date:
Updated on:
Affected Systems:
Sap fi Manager Self-Service
Description:
--------------------------------------------------------------------------------
Bugtraq id: 68951
CVE (CAN) ID: CVE-2014-5176
Sap fi Manager Self-Service is a solution for managing tasks and making decisions.
Sap fi Manager Self-Service has a hard-coded user name, which allows authenticated remote attackers to obtain access permissions.
<* Source: Sergio Abraham
Link: http://www.securityfocus.com/archive/1/archive/1/532945/100/0/threaded
Http://seclists.org/fulldisclosure/2014/Jul/152
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
SAP
---
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://service.sap.com/sap/support/notes/1929473
This article permanently updates the link address: