SAP security note 1905242, "Potential disclosure of persisted data in EHS", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can exploit the Environment, Health, and Safety (EHS) module by using specially crafted inputs to perform SQL injection. This vulnerability allows the attacker to modify database commands and retrieve additional data persisted by the system.
Modification of database commands through SQL injection to access additional persisted data.
Solution
Apply the specified Support Packages. Alternatively, follow the attached correction instructions provided in the SAP Note.
Reason and prerequisites
The vulnerability arises from the application composing SQL statements with user-alterable strings, enabling unauthorized data retrieval.
Affected components
- EA-APPL 600
- EA-APPL 602
- EA-APPL 603
- EA-APPL 604
- EA-APPL 605
- EA-APPL 606
- EA-APPL 616
- EA-APPL 617
- SAP_HRGXX 600
- SAP_HRGXX 604
Full note on SAP: SAP Support Launchpad note 1905242
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
