Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Possible change/disclosure of persisted data in EH&S, SAP security note 1813155

SAP Note 1813155

SAP security note 1813155, “Possible change/disclosure of persisted data in EH&S”. Below is the symptom.

Description

Symptom

An attacker can exploit the Environment, Health, and Safety (EH&S) module by using specially crafted inputs to modify database commands. This can result in the unauthorized modification or disclosure of data persisted by the system.

Reason and prerequisites

The issue arises from an SQL injection vulnerability. The affected code constructs SQL statements by incorporating strings that can be manipulated by an attacker. This manipulation allows the attacker to execute arbitrary SQL commands, potentially leading to unauthorized data access or modification.

References

Full note on SAP: SAP Support Launchpad note 1813155

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More