cbcvebase.

Sap Internet Graphics Server vulnerabilities

28 known vulnerabilities affecting sap/internet_graphics_server.

Total CVEs
28
CISA KEV
0
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL3HIGH10MEDIUM15

Vulnerabilities

Page 1 of 2
CVE-2018-2392P1HIGHCVSS 7.5ExploitedPoCv7.20v7.20ext+3 more2018-02-14
CVE-2018-2392 [HIGH] CWE-611 CVE-2018-2392: Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails t Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
nvd
CVE-2018-2393P3HIGHCVSS 7.5PoCv7.20v7.20ext+3 more2018-02-14
CVE-2018-2393 [HIGH] CWE-611 CVE-2018-2393: Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails t Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
nvd
CVE-2018-2420P3CRITICALCVSS 9.8v7.20v7.20ext+3 more2018-05-09
CVE-2018-2420 [CRITICAL] CWE-434 CVE-2018-2420: SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload an SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper file format validation.
nvd
CVE-2018-2437P3CRITICALCVSS 9.1v7.20v7.20ext+3 more2018-07-10
CVE-2018-2437 [CRITICAL] CVE-2018-2437: The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to exte The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to externally trigger IGS command executions which can lead to: disclosure of information and malicious file insertion or modification.
nvd
CVE-2018-2395P3HIGHCVSS 8.8v7.20v7.20ext+3 more2018-02-14
CVE-2018-2395 [HIGH] CVE-2018-2395: Under certain conditions a malicious user may retrieve information on SAP Internet Graphic Server (I Under certain conditions a malicious user may retrieve information on SAP Internet Graphic Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, overwrite existing image or corrupt other type of files.
nvd
CVE-2006-4133P3HIGHCVSS 7.5v6.40v6.40_patch_11+2 more2006-08-14
CVE-2006-4133 [HIGH] CVE-2006-4133: Heap-based buffer overflow in SAP Internet Graphics Service (IGS) 6.40 and earlier, and 7.00 and ear Heap-based buffer overflow in SAP Internet Graphics Service (IGS) 6.40 and earlier, and 7.00 and earlier, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via an HTTP request with an ADM:GETLOGFILE command and a long portwatcher argument, which triggers the overflow during error message construction when the _snprintf funct
nvd
CVE-2018-2423P3HIGHCVSS 7.5v7.20v7.20ext+3 more2018-05-09
CVE-2018-2423 [HIGH] CVE-2018-2423: SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
nvd
CVE-2007-3613P4MEDIUMCVSS 4.3PoCv6.40v6.40_patch_11+7 more2007-07-06
CVE-2007-3613 [MEDIUM] CVE-2007-3613: Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) al Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) allows remote attackers to inject arbitrary web script or HTML via the PARAMS parameter.
nvd
CVE-2018-2421P3HIGHCVSS 7.5v7.20v7.20ext+3 more2018-05-09
CVE-2018-2421 [HIGH] CVE-2018-2421: SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
nvd
CVE-2018-2422P3HIGHCVSS 7.5v7.20v7.20ext+3 more2018-05-09
CVE-2018-2422 [HIGH] CVE-2018-2422: SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
nvd
CVE-2018-2438P3HIGHCVSS 7.5v7.20v7.20ext+3 more2018-07-10
CVE-2018-2438 [HIGH] CVE-2018-2438: The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has several denial-of-servi The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has several denial-of-service vulnerabilities that allow an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
nvd
CVE-2018-2442P3HIGHCVSS 8.8v7.20v7.20ext+3 more2018-08-14
CVE-2018-2442 [HIGH] CWE-352 CVE-2018-2442: In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelli In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid.
nvd
CVE-2006-6345P4HIGHCVSS 7.5≤ 6.40_patch_16≤ 7.00_patch_32006-12-07
CVE-2006-6345 [HIGH] CVE-2006-6345: Directory traversal vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 16 and earl Directory traversal vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 16 and earlier, and 7.00 Patchlevel 6 and earlier, allows remote attackers to delete arbitrary files via directory traversal sequences in an HTTP request. NOTE: This information is based upon an initial disclosure. Details will be updated after the grace period has ended. T
nvd
CVE-2018-2382P4MEDIUMCVSS 6.5v7.20v7.20ext+3 more2018-02-14
CVE-2018-2382 [MEDIUM] CVE-2018-2382: A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to store graphics in a controlled area and as such gain information from system area, which is not available to the user otherwise.
nvd
CVE-2018-2394P4MEDIUMCVSS 6.5v7.20v7.20ext+3 more2018-02-14
CVE-2018-2394 [MEDIUM] CVE-2018-2394: Under certain conditions an unauthenticated malicious user can prevent legitimate users from accessi Under certain conditions an unauthenticated malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, services and/or system files.
nvd
CVE-2018-2386P4MEDIUMCVSS 6.5v7.20v7.20ext+3 more2018-02-14
CVE-2018-2386 [MEDIUM] CWE-119 CVE-2018-2386: Under certain conditions a malicious user provoking an out of bounds buffer overflow can prevent leg Under certain conditions a malicious user provoking an out of bounds buffer overflow can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53.
nvd
CVE-2018-2387P4MEDIUMCVSS 6.5v7.20v7.20ext+3 more2018-02-14
CVE-2018-2387 [MEDIUM] CVE-2018-2387: A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to obtain information on ports, which is not available to the user otherwise.
nvd
CVE-2018-2439P4MEDIUMCVSS 5.9v7.20v7.20ext+3 more2018-07-10
CVE-2018-2439 [MEDIUM] CWE-20 CVE-2018-2439: The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request va The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request validation (for example, where the request is validated for authenticity and validity) and under certain conditions, will process invalid requests. Several areas of the SAP Internet Graphics Server (IGS) did not require sufficient input validation. Namely,
nvd
CVE-2018-2385P4MEDIUMCVSS 6.5v7.20v7.20ext+3 more2018-02-14
CVE-2018-2385 [MEDIUM] CWE-369 CVE-2018-2385: Under certain conditions a malicious user provoking a divide by zero crash can prevent legitimate us Under certain conditions a malicious user provoking a divide by zero crash can prevent legitimate users from accessing the SAP Internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, and its services.
nvd
CVE-2018-2390P4MEDIUMCVSS 6.5v7.20v7.20ext+3 more2018-02-14
CVE-2018-2390 [MEDIUM] CVE-2018-2390: Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Intern Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, via IGS Chart service.
nvd
Sap Internet Graphics Server vulnerabilities | cvebase