While using a specific function, SAP ERP Defense Forces and Public Security - versions 600, 603, 604, 605, 616, 617, 618, 802, 803, 804, 805, 806, 807, allows an authenticated attacker with admin privileges to write arbitrary data to the syslog file. On successful exploitation, an attacker could modify all the syslog data causing a complete compromise of integrity of the application.
References
Link | Resource |
---|---|
https://me.sap.com/notes/3351410 | Permissions Required |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory |
https://me.sap.com/notes/3351410 | Permissions Required |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:10
Type | Values Removed | Values Added |
---|---|---|
References | () https://me.sap.com/notes/3351410 - Permissions Required | |
References | () https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory |
19 Jul 2023, 18:29
Type | Values Removed | Values Added |
---|---|---|
First Time |
Sap
Sap erp Defense Forces And Public Security |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.9 |
References | (MISC) https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html - Vendor Advisory | |
References | (MISC) https://me.sap.com/notes/3351410 - Permissions Required | |
CPE | cpe:2.3:a:sap:erp_defense_forces_and_public_security:617:*:*:*:*:*:*:* cpe:2.3:a:sap:erp_defense_forces_and_public_security:616:*:*:*:*:*:*:* cpe:2.3:a:sap:erp_defense_forces_and_public_security:806:*:*:*:*:*:*:* cpe:2.3:a:sap:erp_defense_forces_and_public_security:603:*:*:*:*:*:*:* cpe:2.3:a:sap:erp_defense_forces_and_public_security:804:*:*:*:*:*:*:* cpe:2.3:a:sap:erp_defense_forces_and_public_security:807:*:*:*:*:*:*:* cpe:2.3:a:sap:erp_defense_forces_and_public_security:805:*:*:*:*:*:*:* cpe:2.3:a:sap:erp_defense_forces_and_public_security:604:*:*:*:*:*:*:* cpe:2.3:a:sap:erp_defense_forces_and_public_security:802:*:*:*:*:*:*:* cpe:2.3:a:sap:erp_defense_forces_and_public_security:600:*:*:*:*:*:*:* cpe:2.3:a:sap:erp_defense_forces_and_public_security:618:*:*:*:*:*:*:* cpe:2.3:a:sap:erp_defense_forces_and_public_security:605:*:*:*:*:*:*:* cpe:2.3:a:sap:erp_defense_forces_and_public_security:803:*:*:*:*:*:*:* |
11 Jul 2023, 03:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-11 03:15
Updated : 2024-11-21 08:10
NVD link : CVE-2023-36924
Mitre link : CVE-2023-36924
CVE.ORG link : CVE-2023-36924
JSON object : View
Products Affected
sap
- erp_defense_forces_and_public_security
CWE
CWE-117
Improper Output Neutralization for Logs