Search This Blog

Monday, April 11, 2011

SAP Note 1339326 - F&R: Remove hardcoded user name branches in code (security)




Symptom
No symptoms. SAP internal security audit.


Other terms
F&R security


Reason and Prerequisites
Production code makes comparisons between sy-uname and hardcoded values. Security implications are negligible however application may perform unexpectedly if user name matches hardcoded value. These comparisons have now been removed.


Solution
Implement the correction instructions or install the associated SP.




Affected Releases
Software
Component
Release
From
Release
To
Release
And
subsequent
SCM
510
510
510
 
SCM
700
700
700
 


Visit https://service.sap.com/sap/support/notes/1339326 for Correction delivered in Support Package & Corrections Instructions

No comments:

Post a Comment