First published: Thu Apr 10 2014(Updated: )
The Security Audit Log facility in SAP Enhancement Package (EHP) 6 for SAP ERP 6.0 allows remote attackers to modify or delete arbitrary log classes via unspecified vectors. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Enhancement Package | =6.0 | |
SAP ERP | =6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-2748 is considered to be high due to the potential for remote attackers to modify or delete log classes.
To fix CVE-2014-2748, ensure that your SAP Enhancement Package 6 for SAP ERP 6.0 is updated to a version that addresses this vulnerability.
CVE-2014-2748 affects SAP Enhancement Package 6 for SAP ERP 6.0 specifically.
The potential impacts of CVE-2014-2748 include unauthorized modification or deletion of security audit logs.
Currently, there is no widely publicized workaround for CVE-2014-2748 other than applying available patches or updates.