PT-2023-4139 · Sap · Sap Erp Defense Forces/Public Security
Published
2023-07-10
·
Updated
2023-07-19
·
CVE-2023-36924
CVSS v2.0
6.1
Medium
| Vector | AV:N/AC:L/Au:M/C:N/I:C/A:N |
Name of the Vulnerable Software and Affected Versions
SAP ERP Defense Forces and Public Security versions 600 through 807
Description
The issue is related to improper handling of log output, which can be exploited by a remote attacker to overwrite arbitrary files. When using a specific function, an authenticated attacker with admin privileges can write arbitrary data to the syslog file, potentially modifying all syslog data and compromising the application's integrity.
Recommendations
For versions 600 through 807, consider restricting access to the syslog file and limiting the privileges of authenticated users to prevent arbitrary data writing until a fix is available.
As a temporary workaround, consider disabling the specific function that allows writing to the syslog file until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Erp Defense Forces/Public Security