Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

Potential modification/disclosure of persisted data in EH&S, SAP security note 1597660

SAP Note 1597660

SAP security note 1597660, “Potential modification/disclosure of persisted data in EH&S”. Below are the symptom and the affected software components.

Description

Symptom

An attacker can exploit the EH&S module using specially crafted inputs to modify database commands. This vulnerability can lead to the retrieval of additional information or the modification of data persisted by the system. (SQL Injection vulnerability)

Reason and prerequisites

The issue is caused by an SQL injection vulnerability where the code constructs SQL statements with strings that can be manipulated by an attacker, allowing unauthorized data access or modifications.

CVSS

Score 0

References

Affected components

  • Environment, Health, and Safety / Product Compliance > Basic Data and Tools (EHS-BD)

Full note on SAP: SAP Support Launchpad note 1597660

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More

Three identical server cabinets carrying stacks of code of very different heights beside a measuring rule

ABAP Code Security Scan Cost Drivers

What moves the cost of an ABAP code security scan: custom object counts, effective lines, systems in scope, transport gating, triage and retest.