{"api_version":"1","generated_at":"2026-07-23T12:54:25+00:00","cve":"CVE-2023-36922","urls":{"html":"https://cve.report/CVE-2023-36922","api":"https://cve.report/api/cve/CVE-2023-36922.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-36922","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-36922"},"summary":{"title":"CVE-2023-36922","description":"Due to programming error in function module or report, SAP NetWeaver ABAP (IS-OIL) - versions 600, 602, 603, 604, 605, 606, 617, 618, 800, 802, 803, 804, 805, 806, 807, allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension.  On successful exploitation, the attacker can read or modify the system data as well as shut down the system.","state":"PUBLIC","assigner":"cna@sap.com","published_at":"2023-07-11 03:15:00","updated_at":"2023-07-11 12:43:00"},"problem_types":["CWE-78"],"metrics":[],"references":[{"url":"https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html","name":"https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html","refsource":"MISC","tags":[],"title":"Access Denied","mime":"text/html","httpstatus":"403","archivestatus":"429"},{"url":"https://me.sap.com/notes/3350297","name":"https://me.sap.com/notes/3350297","refsource":"MISC","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-36922","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-36922","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2023-36922","ASSIGNER":"cna@sap.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"Due to programming error in function module or report, SAP NetWeaver ABAP (IS-OIL) - versions 600, 602, 603, 604, 605, 606, 617, 618, 800, 802, 803, 804, 805, 806, 807, allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension.  On successful exploitation, the attacker can read or modify the system data as well as shut down the system.\n\n"}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","cweId":"CWE-78"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"SAP_SE","product":{"product_data":[{"product_name":"SAP ECC and SAP S/4HANA (IS-OIL)","version":{"version_data":[{"version_affected":"=","version_value":"600"},{"version_affected":"=","version_value":"602"},{"version_affected":"=","version_value":"603"},{"version_affected":"=","version_value":"604"},{"version_affected":"=","version_value":"605"},{"version_affected":"=","version_value":"606"},{"version_affected":"=","version_value":"617"},{"version_affected":"=","version_value":"618"},{"version_affected":"=","version_value":"800"},{"version_affected":"=","version_value":"802"},{"version_affected":"=","version_value":"803"},{"version_affected":"=","version_value":"804"},{"version_affected":"=","version_value":"805"},{"version_affected":"=","version_value":"806"},{"version_affected":"=","version_value":"807"}]}}]}}]}},"references":{"reference_data":[{"url":"https://me.sap.com/notes/3350297","refsource":"MISC","name":"https://me.sap.com/notes/3350297"},{"url":"https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html","refsource":"MISC","name":"https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html"}]},"generator":{"engine":"Vulnogram 0.1.0-dev"},"source":{"discovery":"UNKNOWN"},"impact":{"cvss":[{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.1,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"HIGH","scope":"CHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H","version":"3.1"}]}},"nvd":{"publishedDate":"2023-07-11 03:15:00","lastModifiedDate":"2023-07-11 12:43:00","problem_types":["CWE-78"],"metrics":[],"configurations":{"CVE_data_version":"4.0","nodes":[]}},"legacy_mitre":{"record":null,"notes":[]}}}