CVE-2018-2389
published 2018-02-14CVE-2018-2389: Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, hiding important…
PriorityP425medium5.7CVSS 3.0
AVNACLPRLUIRSUCNIHAN
EPSS
0.70%
49.3th percentile
Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, hiding important information in the log file.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | internet_graphics_server | — | — |
| sap | internet_graphics_server | — | — |
| sap | internet_graphics_server | — | — |
| sap | internet_graphics_server | — | — |
| sap | internet_graphics_server | — | — |
| sap_se | sap_internet_graphics_server | — | — |
| sap_se | sap_internet_graphics_server | — | — |
| sap_se | sap_internet_graphics_server | — | — |
| sap_se | sap_internet_graphics_server | — | — |
| sap_se | sap_internet_graphics_server | — | — |
CVSS provenance
nvdv3.05.7MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mvp7-h963-xmjh: Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7
ghsa_unreviewed·2022-05-13
CVE-2018-2389 [MEDIUM] CWE-116 GHSA-mvp7-h963-xmjh: Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7
Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, hiding important information in the log file.
Red Hat
mongodb: Incorrect scoping in shipped sysV scripts allows arbitrary PID insertion to kill
vendor_redhat·2019-08-30·CVSS 4.7
CVE-2019-2389 [MEDIUM] CWE-732 mongodb: Incorrect scoping in shipped sysV scripts allows arbitrary PID insertion to kill
mongodb: Incorrect scoping in shipped sysV scripts allows arbitrary PID insertion to kill
Incorrect scoping of kill operations in MongoDB Server's packaged SysV init scripts allow users with write access to the PID file to insert arbitrary PIDs to be killed when the root user stops the MongoDB process via SysV init. This issue affects MongoDB Server v4.0 versions prior to 4.0.11; MongoDB Server v3.6 versions prior to 3.6.14; MongoDB Server v3.4 versions prior to 3.4.22.
Statement: This issue affects the mongodb packages as shipped in the Red Hat Enterprise Linux version 6 release of Red Hat Software Collections. For the Red Hat Enterprise Linux version 7 release of Red Hat Software Collections, refer to systemd CVE-2018-16888.
Red Hat Satellite 6 is using MongoDB, but is not considered v
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2018-02-14
Published