CVE-2023-36924: SAP ERP Defense Forces And Public Security
Medium severity, CVSS 4.9. EPSS: 0.5% chance of exploitation in the next 30 days.
While using a specific function, SAP ERP Defense Forces and Public Security - versions 600, 603, 604, 605, 616, 617, 618, 802, 803, 804, 805, 806, 807, allows an authenticated attacker with admin privileges to write arbitrary data to the syslog file. On successful exploitation, an attacker could modify all the syslog data causing a complete compromise of integrity of the application.
Affected products
- SAP ERP Defense Forces And Public Security: version 600 only; version 603 only; version 604 only; version 605 only; version 616 only; version 617 only; …
Published 2023-07-11. Last modified 2026-06-17.