Lucene search

K
cveSapCVE-2023-36922
HistoryJul 11, 2023 - 3:15 a.m.

CVE-2023-36922

2023-07-1103:15:10
CWE-78
sap
web.nvd.nist.gov
99
sap
netweaver
abap
is-oil
programming error
cve-2023-36922
vulnerability
security
nvd
operating system command

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

8.4

Confidence

High

EPSS

0.001

Percentile

43.4%

Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension. Β On successful exploitation, the attacker can read or modify the system data as well as shut down the system.

Affected configurations

Nvd
Node
sapnetweaverMatch600
OR
sapnetweaverMatch602
OR
sapnetweaverMatch603
OR
sapnetweaverMatch604
OR
sapnetweaverMatch605
OR
sapnetweaverMatch606
OR
sapnetweaverMatch617
OR
sapnetweaverMatch618
OR
sapnetweaverMatch800
OR
sapnetweaverMatch802
OR
sapnetweaverMatch803
OR
sapnetweaverMatch804
OR
sapnetweaverMatch805
OR
sapnetweaverMatch806
OR
sapnetweaverMatch807
VendorProductVersionCPE
sapnetweaver600cpe:2.3:a:sap:netweaver:600:*:*:*:*:*:*:*
sapnetweaver602cpe:2.3:a:sap:netweaver:602:*:*:*:*:*:*:*
sapnetweaver603cpe:2.3:a:sap:netweaver:603:*:*:*:*:*:*:*
sapnetweaver604cpe:2.3:a:sap:netweaver:604:*:*:*:*:*:*:*
sapnetweaver605cpe:2.3:a:sap:netweaver:605:*:*:*:*:*:*:*
sapnetweaver606cpe:2.3:a:sap:netweaver:606:*:*:*:*:*:*:*
sapnetweaver617cpe:2.3:a:sap:netweaver:617:*:*:*:*:*:*:*
sapnetweaver618cpe:2.3:a:sap:netweaver:618:*:*:*:*:*:*:*
sapnetweaver800cpe:2.3:a:sap:netweaver:800:*:*:*:*:*:*:*
sapnetweaver802cpe:2.3:a:sap:netweaver:802:*:*:*:*:*:*:*
Rows per page:
1-10 of 151

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "SAP ECC and SAP S/4HANA (IS-OIL)",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "IS-OIL 600"
      },
      {
        "status": "affected",
        "version": "IS-OIL 602"
      },
      {
        "status": "affected",
        "version": "IS-OIL 603"
      },
      {
        "status": "affected",
        "version": "IS-OIL 604"
      },
      {
        "status": "affected",
        "version": "IS-OIL 605"
      },
      {
        "status": "affected",
        "version": "IS-OIL 606"
      },
      {
        "status": "affected",
        "version": "IS-OIL 617"
      },
      {
        "status": "affected",
        "version": "IS-OIL 618"
      },
      {
        "status": "affected",
        "version": "IS-OIL 800"
      },
      {
        "status": "affected",
        "version": "IS-OIL 802"
      },
      {
        "status": "affected",
        "version": "IS-OIL 803"
      },
      {
        "status": "affected",
        "version": "IS-OIL 804"
      },
      {
        "status": "affected",
        "version": "IS-OIL 805"
      },
      {
        "status": "affected",
        "version": "IS-OIL 806"
      },
      {
        "status": "affected",
        "version": "IS-OIL 807"
      }
    ]
  }
]

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

8.4

Confidence

High

EPSS

0.001

Percentile

43.4%

Related for CVE-2023-36922