SAP security note 1813155, “Possible change/disclosure of persisted data in EH&S”. Below is the symptom.
Description
Symptom
An attacker can exploit the Environment, Health, and Safety (EH&S) module by using specially crafted inputs to modify database commands. This can result in the unauthorized modification or disclosure of data persisted by the system.
Reason and prerequisites
The issue arises from an SQL injection vulnerability. The affected code constructs SQL statements by incorporating strings that can be manipulated by an attacker. This manipulation allows the attacker to execute arbitrary SQL commands, potentially leading to unauthorized data access or modification.
References
- 1122425 – Filling: Filtering specifications
- 1597660 – Potential modification/disclosure of persisted data in EH&S
Full note on SAP: SAP Support Launchpad note 1813155
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
