Skip links
Arpine Maghakyan

Arpine Maghakyan

Security Researcher of RedRays.

PM ES Potential disclosure and modification of DB data, SAP security note 1503358

Description

A malicious user can exploit the enterprise service MaintenanceTaskListERPSimpleByElementsQueryResponse_In_V1 and use specially crafted inputs to execute arbitrary database commands to retrieve, modify, or remove data persisted by the system.

Available fix and Supported packages

  • SAP_APPL | 605 | 605
  • SAP_APPL 605 | SAPKH60502 |

Affected component

    PM-ES
    Enterprise Services in Plant Maintenance

CVSS

Score: 0

Exploit

Exploit is not available.
For detailed information please contact the mail [email protected].

URL

https://launchpad.support.sap.com/#/notes/1503358

TAGS

#SQL-injection
#database
#CL_EAM_MAINTTSKLIST001QR1
#PM-ES

More to explorer