cbcvebase.
CVE-2023-36922
published 2023-07-11

CVE-2023-36922: Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary…

PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.84%
53.7th percentile
Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension. On successful exploitation, the attacker can read or modify the system data as well as shut down the system.

Affected

30 ranges· showing 25
VendorProductVersion rangeFixed in
sapnetweaver
sapnetweaver
sapnetweaver
sapnetweaver
sapnetweaver
sapnetweaver
sapnetweaver
sapnetweaver
sapnetweaver
sapnetweaver
sapnetweaver
sapnetweaver
sapnetweaver
sapnetweaver
sapnetweaver
sap_sesap_ecc_and_sap_s_4hana
sap_sesap_ecc_and_sap_s_4hana
sap_sesap_ecc_and_sap_s_4hana
sap_sesap_ecc_and_sap_s_4hana
sap_sesap_ecc_and_sap_s_4hana
sap_sesap_ecc_and_sap_s_4hana
sap_sesap_ecc_and_sap_s_4hana
sap_sesap_ecc_and_sap_s_4hana
sap_sesap_ecc_and_sap_s_4hana
sap_sesap_ecc_and_sap_s_4hana
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.