Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension. On successful exploitation, the attacker can read or modify the system data as well as shut down the system.
Use CWE-78, Sap vendor hub and Netweaver product page to widen CVE-2023-36922 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-31324, CVE-2025-42999 and CVE-2023-33984 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 13th, 2026.