CVE-2023-36922: OS command injection vulnerability in SAP ECC and SAP S/4HANA (IS-OIL)
Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension. On successful exploitation, the attacker can read or modify the system data as well as shut down the system.
Other sources
Due to programming error in function module or report, SAP NetWeaver ABAP (IS-OIL) - versions 600, 602, 603, 604, 605, 606, 617, 618, 800, 802, 803, 804, 805, 806, 807, allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension. On successful exploitation, the attacker can read or modify the system data as well as shut down the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-36922?
The severity of CVE-2023-36922 is critical.
What is the common vulnerability and exposure ID for SAP NetWeaver ABAP (IS-OIL) version 600?
The common vulnerability and exposure ID for SAP NetWeaver ABAP (IS-OIL) version 600 is CVE-2023-36922.
How does CVE-2023-36922 affect SAP NetWeaver ABAP (IS-OIL)?
CVE-2023-36922 allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) module or report.
How can I fix CVE-2023-36922 in SAP NetWeaver ABAP (IS-OIL)?
Apply the necessary security patches provided by SAP to fix CVE-2023-36922 in SAP NetWeaver ABAP (IS-OIL).
Where can I find more information about CVE-2023-36922?
You can find more information about CVE-2023-36922 at the following references: [Link 1](https://me.sap.com/notes/3350297) and [Link 2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).