Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Possible change/disclosure of persisted data in EH&S, SAP security note 1810405

SAP Note 1810405
SAP Security Note
Medium priority

SAP security note 1810405, “Possible change/disclosure of persisted data in EH&S”, is a program error note released on 24.09.2014. Below are the symptom and SAP recommended solution.

ComponentEnvironment, Health, and Safety / Product Compliance > Product Safety (EHS-SAF)
CategoryProgram error
PriorityCorrection with medium priority
TypeSAP Security Note
Version1
StatusReleased for Customer
Released on24.09.2014
LanguageEnglish

Description

Symptom

An attacker can exploit EHS and use specially crafted inputs to modify database commands, resulting in the modification or display of data persisted by the system.

Solution

Refer to the “Support Package” section below for information on which Support Packages contain the necessary corrections. Alternatively, you can implement the provided correction instructions.

Reason and prerequisites

The issue is caused by an SQL injection vulnerability. The code constructs an SQL statement using strings that can be manipulated by an attacker. This manipulated SQL statement can then be used to retrieve additional data from the database or modify existing data.

CVSS

Score 0

Full note on SAP: SAP Support Launchpad note 1810405

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More