CVE-2018-2420

Severity
9.8CRITICAL
EPSS
0.6%
top 29.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 9
Latest updateMay 13

Description

SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper file format validation.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:HExploitability: 2.2 | Impact: 4.2

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-ghqr-5fq8-7vx6: SAP Internet Graphics Server (IGS), 72022-05-13
CVEList
CVE-2018-2420: SAP Internet Graphics Server (IGS), 72018-05-09
CVE-2018-2420 (CRITICAL CVSS 9.8) | SAP Internet Graphics Server (IGS) | cvebase.io