CVE-2018-2437
published 2018-07-10CVE-2018-2437: The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to externally trigger IGS command executions which can lead to…
PriorityP346critical9.1CVSS 3.0
AVNACLPRNUINSUCHIHAN
EPSS
3.30%
87.1th percentile
The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to externally trigger IGS command executions which can lead to: disclosure of information and malicious file insertion or modification.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| juniper | junos_os | — | — |
| juniper | qfx_series | — | — |
| sap | internet_graphics_server | — | — |
| sap | internet_graphics_server | — | — |
| sap | internet_graphics_server | — | — |
| sap | internet_graphics_server | — | — |
| sap | internet_graphics_server | — | — |
| sap | sap_internet_graphics_server | — | — |
| sap | sap_internet_graphics_server | — | — |
| sap | sap_internet_graphics_server | — | — |
| sap | sap_internet_graphics_server | — | — |
| sap | sap_internet_graphics_server | — | — |
CVSS provenance
nvdv3.09.1CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9xc3-6q7f-rvjp: The SAP Internet Graphics Service (IGS), 7
ghsa_unreviewed·2022-05-13
CVE-2018-2437 [CRITICAL] GHSA-9xc3-6q7f-rvjp: The SAP Internet Graphics Service (IGS), 7
The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to externally trigger IGS command executions which can lead to: disclosure of information and malicious file insertion or modification.
Juniper
CVE-2018-0022: A Junos device with VPLS routing-instances configured on one or more interfaces may be susceptible to an mbuf leak when processing a specific MPLS pac
vendor_juniper·2018-04-11·CVSS 7.5
CVE-2018-0022 [HIGH] CWE-400 CVE-2018-0022: A Junos device with VPLS routing-instances configured on one or more interfaces may be susceptible to an mbuf leak when processing a specific MPLS pac
CVE-2018-0022: A Junos device with VPLS routing-instances configured on one or more interfaces may be susceptible to an mbuf leak when processing a specific MPLS packet. Approximately 1 mbuf is leaked per each packet processed. The number of mbufs is platform dependent. The following command provides the number of mbufs that are currently in use and maximum number of mbufs that can be allocated on a platform: > show system buffers 2437/3143/5580 mbufs in use (current/cache/total) Once the device runs out of mbufs it will become inaccessible and a restart will be required. This issue only affects end devices, transit devices are not affected. Affected releases are Juniper Networks Junos OS with VPLS configured running: 12.1X46 versions prior to 12.1X46-D76; 12.3X48 versions prior to 12.3X48
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/104705https://launchpad.support.sap.com/#/notes/2644227https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000http://www.securityfocus.com/bid/104705https://launchpad.support.sap.com/#/notes/2644227https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000
2018-07-10
Published