CVE-2014-2748
Severity CVSS v4.0:
Pending analysis
Type:
CWE-264
Permissions, Privileges, and Access Control
Publication date:
10/04/2014
Last modified:
12/04/2025
Description
The Security Audit Log facility in SAP Enhancement Package (EHP) 6 for SAP ERP 6.0 allows remote attackers to modify or delete arbitrary log classes via unspecified vectors. NOTE: some of these details are obtained from third party information.
Impact
Base Score 2.0
7.50
Severity 2.0
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:sap:enhancement_package:6.0:*:*:*:*:*:*:* | ||
cpe:2.3:a:sap:erp:6.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://secunia.com/advisories/57741
- http://www.onapsis.com/get.php?resid=adv_onapsis-2014-002
- http://www.onapsis.com/research-advisories.php
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92334
- https://service.sap.com/sap/support/notes/1926485
- http://secunia.com/advisories/57741
- http://www.onapsis.com/get.php?resid=adv_onapsis-2014-002
- http://www.onapsis.com/research-advisories.php
- https://exchange.xforce.ibmcloud.com/vulnerabilities/92334
- https://service.sap.com/sap/support/notes/1926485