SAP Security Note
Medium priority
SAP security note 1810405, “Possible change/disclosure of persisted data in EH&S”, is a program error note released on 24.09.2014. Below are the symptom and SAP recommended solution.
Description
Symptom
An attacker can exploit EHS and use specially crafted inputs to modify database commands, resulting in the modification or display of data persisted by the system.
Solution
Refer to the “Support Package” section below for information on which Support Packages contain the necessary corrections. Alternatively, you can implement the provided correction instructions.
Reason and prerequisites
The issue is caused by an SQL injection vulnerability. The code constructs an SQL statement using strings that can be manipulated by an attacker. This manipulated SQL statement can then be used to retrieve additional data from the database or modify existing data.
CVSS
Score 0
Full note on SAP: SAP Support Launchpad note 1810405
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
