4.9
CVE-2023-36924
- EPSS 0.47%
- Veröffentlicht 11.07.2023 03:15:10
- Zuletzt bearbeitet 21.11.2024 08:10:56
- Erkennungen
Log Injection vulnerability in SAP ERP Defense Forces and Public Security
While using a specific function, SAP ERP Defense Forces and Public Security - versions 600, 603, 604, 605, 616, 617, 618, 802, 803, 804, 805, 806, 807, allows an authenticated attacker with admin privileges to write arbitrary data to the syslog file. On successful exploitation, an attacker could modify all the syslog data causing a complete compromise of integrity of the application.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Erp Defense Forces And Public Security Version 600
SAP ≫ Erp Defense Forces And Public Security Version 603
SAP ≫ Erp Defense Forces And Public Security Version 604
SAP ≫ Erp Defense Forces And Public Security Version 605
SAP ≫ Erp Defense Forces And Public Security Version 616
SAP ≫ Erp Defense Forces And Public Security Version 617
SAP ≫ Erp Defense Forces And Public Security Version 618
SAP ≫ Erp Defense Forces And Public Security Version 802
SAP ≫ Erp Defense Forces And Public Security Version 803
SAP ≫ Erp Defense Forces And Public Security Version 804
SAP ≫ Erp Defense Forces And Public Security Version 805
SAP ≫ Erp Defense Forces And Public Security Version 806
SAP ≫ Erp Defense Forces And Public Security Version 807
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.47% | 0.377 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
|
| SAP | 4.9 | 1.2 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
|
CWE-117 Improper Output Neutralization for Logs
The product constructs a log message from external input, but it does not neutralize or incorrectly neutralizes special elements when the message is written to a log file.
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
https://me.sap.com/notes/3351410