First published: Mon Jun 09 2014(Updated: )
The (1) Structures and (2) Project-Oriented Procurement components in SAP Project System has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Project System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4004 is rated as a high severity vulnerability due to its potential for remote exploitation through hardcoded credentials.
To mitigate CVE-2014-4004, it is recommended to update to a patched version of SAP Project System where the hardcoded credentials have been removed.
CVE-2014-4004 allows remote attackers to gain unauthorized access to the SAP Project System due to the presence of hardcoded credentials.
Organizations using SAP Project System with the vulnerable components are at risk due to CVE-2014-4004.
While the best solution is to apply the update, temporary access restrictions and monitoring could serve as a workaround for CVE-2014-4004.