CVE-2006-4134
published 2006-08-14CVE-2006-4134: Unspecified vulnerability related to a "design flaw" in SAP Internet Graphics Service (IGS) 6.40 and earlier and 7.00 and earlier allows remote attackers to…
PriorityP420medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
4.58%
90.5th percentile
Unspecified vulnerability related to a "design flaw" in SAP Internet Graphics Service (IGS) 6.40 and earlier and 7.00 and earlier allows remote attackers to cause a denial of service (service shutdown) via certain HTTP requests. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | internet_graphics_server | <= 6.40_patch_15 | — |
| sap | internet_graphics_server | <= 7.00_patch_3 | — |
| sap | internet_graphics_server | <= 6.40_patch_16 | — |
| sap | internet_graphics_server | — | — |
| sap | internet_graphics_server | — | — |
| sap | internet_graphics_server | — | — |
| sap | internet_graphics_server | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-234f-wm58-6qqv: Directory traversal vulnerability in SAP Internet Graphics Service (IGS) 6
ghsa_unreviewed·2022-05-01·CVSS 7.5
CVE-2006-6345 [HIGH] GHSA-234f-wm58-6qqv: Directory traversal vulnerability in SAP Internet Graphics Service (IGS) 6
Directory traversal vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 16 and earlier, and 7.00 Patchlevel 6 and earlier, allows remote attackers to delete arbitrary files via directory traversal sequences in an HTTP request. NOTE: This information is based upon an initial disclosure. Details will be updated after the grace period has ended. This issue is different from CVE-2006-4133 and CVE-2006-4134.
GHSA
GHSA-7h68-rrpv-45xm: Unspecified vulnerability related to a "design flaw" in SAP Internet Graphics Service (IGS) 6
ghsa_unreviewed·2022-05-01
CVE-2006-4134 [MEDIUM] GHSA-7h68-rrpv-45xm: Unspecified vulnerability related to a "design flaw" in SAP Internet Graphics Service (IGS) 6
Unspecified vulnerability related to a "design flaw" in SAP Internet Graphics Service (IGS) 6.40 and earlier and 7.00 and earlier allows remote attackers to cause a denial of service (service shutdown) via certain HTTP requests. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
GHSA
GHSA-8wq9-m359-crgc: Unspecified vulnerability in SAP Internet Graphics Service (IGS) 6
ghsa_unreviewed·2022-05-01·CVSS 5.0
CVE-2006-6346 [MEDIUM] GHSA-8wq9-m359-crgc: Unspecified vulnerability in SAP Internet Graphics Service (IGS) 6
Unspecified vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 15 and earlier, and 7.00 Patchlevel 3 and earlier, allows remote attackers to cause a denial of service (service shutdown), obtain sensitive information (configuration files), and conduct certain other unauthorized activities, related to "Undocumented Features." NOTE: it is possible that there are multiple issues. This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended. This is likely a different issue than CVE-2006-4134.
No detection rules found.
No public exploits indexed.
http://marc.info/?l=bugtraq&m=115524314804055&w=2http://secunia.com/advisories/21448http://securityreason.com/securityalert/1390http://securitytracker.com/id?1016675http://www.cybsec.com/vuln/CYBSEC-Security_Pre-Advisory_SAP_IGS_Remote_Denial_of_Service.pdfhttp://www.securityfocus.com/archive/1/442838/100/0/threadedhttp://www.securityfocus.com/bid/19469http://www.vupen.com/english/advisories/2006/3267https://exchange.xforce.ibmcloud.com/vulnerabilities/28328http://marc.info/?l=bugtraq&m=115524314804055&w=2http://secunia.com/advisories/21448http://securityreason.com/securityalert/1390http://securitytracker.com/id?1016675http://www.cybsec.com/vuln/CYBSEC-Security_Pre-Advisory_SAP_IGS_Remote_Denial_of_Service.pdfhttp://www.securityfocus.com/archive/1/442838/100/0/threadedhttp://www.securityfocus.com/bid/19469http://www.vupen.com/english/advisories/2006/3267https://exchange.xforce.ibmcloud.com/vulnerabilities/28328
2006-08-14
Published