VYPR
Critical severity9.1NVD Advisory· Published Jul 11, 2023· Updated Jun 17, 2026

CVE-2023-36922

CVE-2023-36922

Description

Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension.  On successful exploitation, the attacker can read or modify the system data as well as shut down the system.

Affected products

17
  • SAP/Netweaver15 versions
    cpe:2.3:a:sap:netweaver:600:*:*:*:*:*:*:*+ 14 more
    • cpe:2.3:a:sap:netweaver:600:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:netweaver:602:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:netweaver:603:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:netweaver:604:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:netweaver:605:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:netweaver:606:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:netweaver:617:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:netweaver:618:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:netweaver:800:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:netweaver:802:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:netweaver:803:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:netweaver:804:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:netweaver:805:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:netweaver:806:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:netweaver:807:*:*:*:*:*:*:*
  • SAP/IS-OILllm-create
  • SAP_SE/SAP ECC and SAP S/4HANA (IS-OIL)v5
    Range: IS-OIL 600

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.