2023-07-19 23:55:40 +00:00

162 lines
5.6 KiB
JSON

{
"id": "CVE-2023-36924",
"sourceIdentifier": "cna@sap.com",
"published": "2023-07-11T03:15:10.417",
"lastModified": "2023-07-19T18:29:41.167",
"vulnStatus": "Analyzed",
"descriptions": [
{
"lang": "en",
"value": "While using a specific function, SAP ERP Defense Forces and Public Security - versions 600, 603, 604, 605, 616, 617, 618, 802, 803, 804, 805, 806, 807, allows an authenticated attacker with admin privileges to write arbitrary data to the syslog file. On successful exploitation, an attacker could modify all the syslog data causing a complete compromise of integrity of the application.\n\n"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE",
"baseScore": 4.9,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 1.2,
"impactScore": 3.6
},
{
"source": "cna@sap.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "NONE",
"integrityImpact": "HIGH",
"availabilityImpact": "NONE",
"baseScore": 4.9,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 1.2,
"impactScore": 3.6
}
]
},
"weaknesses": [
{
"source": "cna@sap.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-117"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:erp_defense_forces_and_public_security:600:*:*:*:*:*:*:*",
"matchCriteriaId": "165083A6-F783-4DF8-BACA-F8322127B367"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:erp_defense_forces_and_public_security:603:*:*:*:*:*:*:*",
"matchCriteriaId": "EB212350-1381-411E-A8EF-E42DE7F456AC"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:erp_defense_forces_and_public_security:604:*:*:*:*:*:*:*",
"matchCriteriaId": "94C10D8C-34AB-435B-A5CD-24BEBCC626ED"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:erp_defense_forces_and_public_security:605:*:*:*:*:*:*:*",
"matchCriteriaId": "211D94F2-4D3F-4BD5-B072-7B6759159B5F"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:erp_defense_forces_and_public_security:616:*:*:*:*:*:*:*",
"matchCriteriaId": "A64661D0-94E6-4F55-AB7A-055E10A799DD"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:erp_defense_forces_and_public_security:617:*:*:*:*:*:*:*",
"matchCriteriaId": "89E96E9D-A9EF-4A55-9DC1-755B97768B29"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:erp_defense_forces_and_public_security:618:*:*:*:*:*:*:*",
"matchCriteriaId": "1B9EBD4C-AFCD-4B4F-AB57-FE00C21F2B61"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:erp_defense_forces_and_public_security:802:*:*:*:*:*:*:*",
"matchCriteriaId": "67FF541F-7B4D-48A8-8CAF-D4B5923B3631"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:erp_defense_forces_and_public_security:803:*:*:*:*:*:*:*",
"matchCriteriaId": "BC80872A-80F9-496C-AE97-958E8FCE0BCE"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:erp_defense_forces_and_public_security:804:*:*:*:*:*:*:*",
"matchCriteriaId": "92030B39-9065-4EE3-8475-B86FBB1B622D"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:erp_defense_forces_and_public_security:805:*:*:*:*:*:*:*",
"matchCriteriaId": "C31AEB42-A823-4344-8135-ACA063E4C41A"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:erp_defense_forces_and_public_security:806:*:*:*:*:*:*:*",
"matchCriteriaId": "F2CD6245-D1FE-41A2-8295-E69F331428CB"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:erp_defense_forces_and_public_security:807:*:*:*:*:*:*:*",
"matchCriteriaId": "FB9AC6AC-455D-40E7-AD6B-47FCEB5B4D5A"
}
]
}
]
}
],
"references": [
{
"url": "https://me.sap.com/notes/3351410",
"source": "cna@sap.com",
"tags": [
"Permissions Required"
]
},
{
"url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html",
"source": "cna@sap.com",
"tags": [
"Vendor Advisory"
]
}
]
}