First published: Mon Jun 09 2014(Updated: )
The SAP Trader's and Scheduler's Workbench (TSW) for SAP Oil & Gas has hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Oil Industry Solution Traders and Schedulers Workbench | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4006 is considered a high severity vulnerability due to the presence of hardcoded credentials allowing unauthorized access.
To fix CVE-2014-4006, it is recommended to update to the latest version of the SAP TSW that disables hardcoded credentials.
Exploiting CVE-2014-4006 can allow attackers to gain unauthorized access to the SAP Trader's and Scheduler's Workbench, potentially compromising sensitive data.
CVE-2014-4006 affects versions of the SAP Oil Industry Solution Trader's and Scheduler's Workbench with hardcoded credentials.
Currently, there are no official workarounds for CVE-2014-4006 other than applying the security updates provided by SAP.