← Back

CVE-2023-36922

nvd nist
Published: Jul 11, 2023Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension.  On successful exploitation, the attacker can read or modify the system data as well as shut down the system.

Affected (15)

Products: Sap: Netweaver
1 product
Netweaver
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Sap
Version 600
Version 602
Version 603
Version 604
Version 605
Version 606
Version 617
Version 618
Version 800
Version 802
Version 803
Version 804
Version 805
Version 806
Version 807

References (4)

Source: cna@sap.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.