Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension. On successful exploitation, the attacker can read or modify the system data as well as shut down the system.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HSap Netweaver
APPSap600602603604605606617618800802803804805806807
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
Related vulnerabilities
CVE-2025-42999CRITICAL9.1⚠ KEVPL ✓same product
SAP NetWeaver Visual Composer — niebezpieczna deserializacja treści
CVE-2025-31324CRITICAL10.0⚠ KEVPL ✓same product
SAP NetWeaver: nieautoryzowany upload plików wykonywalnych w Visual Composer
CVE-2021-38163CRITICAL9.9⚠ KEVPL ✓same product
SAP NetWeaver Visual Composer — RCE przez path traversal przy uploadzie pliku
CVE-2020-6203CRITICAL9.1PL ✓same product
Path Traversal w SAP NetWeaver UDDI Server (Services Registry)
CVE-2011-1517CRITICAL9.8PL ✓same product
SAP NetWeaver 7.0 — RCE i DoS przez błąd w funkcji DiagTraceHex()