CVE-2018-2389

Severity
5.7MEDIUM
EPSS
0.2%
top 57.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 14
Latest updateMay 13

Description

Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, hiding important information in the log file.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:NExploitability: 2.1 | Impact: 3.6

Affected Packages2 packages

CVEListV5sap_se/sap_internet_graphics_server5 versions+4

🔴Vulnerability Details

2
GHSA
GHSA-mvp7-h963-xmjh: Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 72022-05-13
CVEList
CVE-2018-2389: Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 72018-02-14

📋Vendor Advisories

1
Red Hat
mongodb: Incorrect scoping in shipped sysV scripts allows arbitrary PID insertion to kill2019-08-30
CVE-2018-2389 (MEDIUM CVSS 5.7) | Under certain conditions a maliciou | cvebase.io