SAP security note 1597660, “Potential modification/disclosure of persisted data in EH&S”. Below are the symptom and the affected software components.
Description
Symptom
An attacker can exploit the EH&S module using specially crafted inputs to modify database commands. This vulnerability can lead to the retrieval of additional information or the modification of data persisted by the system. (SQL Injection vulnerability)
Reason and prerequisites
The issue is caused by an SQL injection vulnerability where the code constructs SQL statements with strings that can be manipulated by an attacker, allowing unauthorized data access or modifications.
CVSS
Score 0
References
This note refers to
Affected components
- Environment, Health, and Safety / Product Compliance > Basic Data and Tools (EHS-BD)
Full note on SAP: SAP Support Launchpad note 1597660
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].




