CVE-2023-36922: SAP NetWeaver
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension. On successful exploitation, the attacker can read or modify the system data as well as shut down the system.
Affected products
- SAP NetWeaver: version 600 only; version 602 only; version 603 only; version 604 only; version 605 only; version 606 only; …
Published 2023-07-11. Last modified 2026-06-17.