Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential disclosure of persisted data in EHS, SAP security note 1905242

SAP Note 1905242

SAP security note 1905242, "Potential disclosure of persisted data in EHS", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

An attacker can exploit the Environment, Health, and Safety (EHS) module by using specially crafted inputs to perform SQL injection. This vulnerability allows the attacker to modify database commands and retrieve additional data persisted by the system.

Modification of database commands through SQL injection to access additional persisted data.

Solution

Apply the specified Support Packages. Alternatively, follow the attached correction instructions provided in the SAP Note.

Reason and prerequisites

The vulnerability arises from the application composing SQL statements with user-alterable strings, enabling unauthorized data retrieval.

Affected components

  • EA-APPL 600
  • EA-APPL 602
  • EA-APPL 603
  • EA-APPL 604
  • EA-APPL 605
  • EA-APPL 606
  • EA-APPL 616
  • EA-APPL 617
  • SAP_HRGXX 600
  • SAP_HRGXX 604

Full note on SAP: SAP Support Launchpad note 1905242

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More