CVE Published: 11/07/2023 |
CVE Updated: 02/08/2024 |
CVE Year: 2023 Source: sap |
Vendor: SAP_SE |
Product: SAP ECC and SAP S/4HANA (IS-OIL) Status : PUBLISHED
CVE-2023-36922 Description
Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension. On successful exploitation, the attacker can read or modify the system data as well as shut down the system.
Metrics
CVSS Version: 3.1 |
Base Score: 9.1 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H