CVE-2023-36924
Summary
| CVE | CVE-2023-36924 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-11 03:15:00 UTC |
| Updated | 2023-07-19 18:29:00 UTC |
| Description | While using a specific function, SAP ERP Defense Forces and Public Security - versions 600, 603, 604, 605, 616, 617, 618, 802, 803, 804, 805, 806, 807, allows an authenticated attacker with admin privileges to write arbitrary data to the syslog file. On successful exploitation, an attacker could modify all the syslog data causing a complete compromise of integrity of the application. |
Risk And Classification
Problem Types: CWE-117
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Erp Defense Forces And Public Security | 600 | All | All | All |
| Application | Sap | Erp Defense Forces And Public Security | 603 | All | All | All |
| Application | Sap | Erp Defense Forces And Public Security | 604 | All | All | All |
| Application | Sap | Erp Defense Forces And Public Security | 605 | All | All | All |
| Application | Sap | Erp Defense Forces And Public Security | 616 | All | All | All |
| Application | Sap | Erp Defense Forces And Public Security | 617 | All | All | All |
| Application | Sap | Erp Defense Forces And Public Security | 618 | All | All | All |
| Application | Sap | Erp Defense Forces And Public Security | 802 | All | All | All |
| Application | Sap | Erp Defense Forces And Public Security | 803 | All | All | All |
| Application | Sap | Erp Defense Forces And Public Security | 804 | All | All | All |
| Application | Sap | Erp Defense Forces And Public Security | 805 | All | All | All |
| Application | Sap | Erp Defense Forces And Public Security | 806 | All | All | All |
| Application | Sap | Erp Defense Forces And Public Security | 807 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| me.sap.com/notes/3351410 | MISC | me.sap.com | |
| Access Denied | MISC | www.sap.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.