Lucene search

K
cvelistSapCVELIST:CVE-2023-36922
HistoryJul 11, 2023 - 2:56 a.m.

CVE-2023-36922 OS command injection vulnerability in SAP ECC and SAP S/4HANA (IS-OIL)

2023-07-1102:56:55
CWE-78
sap
www.cve.org
6
sap
ecc
s/4hana
is-oil
command injection
vulnerability
programming error
authenticated attacker
data exposure
system shutdown

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.001

Percentile

43.4%

Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension. Β On successful exploitation, the attacker can read or modify the system data as well as shut down the system.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "SAP ECC and SAP S/4HANA (IS-OIL)",
    "vendor": "SAP_SE",
    "versions": [
      {
        "status": "affected",
        "version": "IS-OIL 600"
      },
      {
        "status": "affected",
        "version": "IS-OIL 602"
      },
      {
        "status": "affected",
        "version": "IS-OIL 603"
      },
      {
        "status": "affected",
        "version": "IS-OIL 604"
      },
      {
        "status": "affected",
        "version": "IS-OIL 605"
      },
      {
        "status": "affected",
        "version": "IS-OIL 606"
      },
      {
        "status": "affected",
        "version": "IS-OIL 617"
      },
      {
        "status": "affected",
        "version": "IS-OIL 618"
      },
      {
        "status": "affected",
        "version": "IS-OIL 800"
      },
      {
        "status": "affected",
        "version": "IS-OIL 802"
      },
      {
        "status": "affected",
        "version": "IS-OIL 803"
      },
      {
        "status": "affected",
        "version": "IS-OIL 804"
      },
      {
        "status": "affected",
        "version": "IS-OIL 805"
      },
      {
        "status": "affected",
        "version": "IS-OIL 806"
      },
      {
        "status": "affected",
        "version": "IS-OIL 807"
      }
    ]
  }
]

CVSS3

9.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

9.2

Confidence

High

EPSS

0.001

Percentile

43.4%

Related for CVELIST:CVE-2023-36922