CVE-2023-36922
published 2023-07-11CVE-2023-36922: Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary…
PriorityP356high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.84%
53.7th percentile
Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension. On successful exploitation, the attacker can read or modify the system data as well as shut down the system.
Affected
30 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | netweaver | — | — |
| sap | netweaver | — | — |
| sap | netweaver | — | — |
| sap | netweaver | — | — |
| sap | netweaver | — | — |
| sap | netweaver | — | — |
| sap | netweaver | — | — |
| sap | netweaver | — | — |
| sap | netweaver | — | — |
| sap | netweaver | — | — |
| sap | netweaver | — | — |
| sap | netweaver | — | — |
| sap | netweaver | — | — |
| sap | netweaver | — | — |
| sap | netweaver | — | — |
| sap_se | sap_ecc_and_sap_s_4hana | — | — |
| sap_se | sap_ecc_and_sap_s_4hana | — | — |
| sap_se | sap_ecc_and_sap_s_4hana | — | — |
| sap_se | sap_ecc_and_sap_s_4hana | — | — |
| sap_se | sap_ecc_and_sap_s_4hana | — | — |
| sap_se | sap_ecc_and_sap_s_4hana | — | — |
| sap_se | sap_ecc_and_sap_s_4hana | — | — |
| sap_se | sap_ecc_and_sap_s_4hana | — | — |
| sap_se | sap_ecc_and_sap_s_4hana | — | — |
| sap_se | sap_ecc_and_sap_s_4hana | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-07-11
Published