CVE-2023-36922

HIGHCVSS 8.8/10EPSS 0.70%

Last modified

CVE-2023-36922 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension.  On successful exploitation, the attacker can read or modify the system data as well as shut down the system. . EPSS estimates a 0.70% chance of exploitation in the next 30 days.

Description

Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension.  On successful exploitation, the attacker can read or modify the system data as well as shut down the system.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.70%

48.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
SapNetweaver600
SapNetweaver602
SapNetweaver603
SapNetweaver604
SapNetweaver605
SapNetweaver606
SapNetweaver617
SapNetweaver618
SapNetweaver800
SapNetweaver802
SapNetweaver803
SapNetweaver804
SapNetweaver805
SapNetweaver806
SapNetweaver807

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-36922?
Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension.  On successful exploitation, the attacker can read or modify the system data as well as shut down the system.
How severe is CVE-2023-36922?
CVE-2023-36922 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.70% probability of exploitation in the next 30 days.
How do I fix CVE-2023-36922?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-36922?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST