Sap Internet Graphics Server vulnerabilities

28 known vulnerabilities affecting sap/internet_graphics_server.

Total CVEs
28
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH10MEDIUM15

Vulnerabilities

Page 2 of 2
CVE-2018-2389MEDIUMCVSS 5.7v7.20v7.20ext+3 more2018-02-14
CVE-2018-2389 [MEDIUM] CWE-116 CVE-2018-2389: Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS) Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, hiding important information in the log file.
nvd
CVE-2018-2384MEDIUMCVSS 6.5v7.20v7.20ext+3 more2018-02-14
CVE-2018-2384 [MEDIUM] CWE-476 CVE-2018-2384: Under certain conditions a malicious user provoking a Null Pointer dereference can prevent legitimat Under certain conditions a malicious user provoking a Null Pointer dereference can prevent legitimate users from accessing the SAP Internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, and its services.
nvd
CVE-2018-2382MEDIUMCVSS 6.5v7.20v7.20ext+3 more2018-02-14
CVE-2018-2382 [MEDIUM] CVE-2018-2382: A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to store graphics in a controlled area and as such gain information from system area, which is not available to the user otherwise.
nvd
CVE-2007-3613MEDIUMCVSS 4.3PoCv6.40v6.40_patch_11+7 more2007-07-06
CVE-2007-3613 [MEDIUM] CVE-2007-3613: Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) al Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) allows remote attackers to inject arbitrary web script or HTML via the PARAMS parameter.
nvd
CVE-2006-6346CRITICALCVSS 10.0≤ 6.40_patch_15≤ 7.00_patch_32006-12-07
CVE-2006-6346 [CRITICAL] CVE-2006-6346: Unspecified vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 15 and earlier, and Unspecified vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 15 and earlier, and 7.00 Patchlevel 3 and earlier, allows remote attackers to cause a denial of service (service shutdown), obtain sensitive information (configuration files), and conduct certain other unauthorized activities, related to "Undocumented Features." NOTE: it is pos
nvd
CVE-2006-6345HIGHCVSS 7.5≤ 6.40_patch_16≤ 7.00_patch_32006-12-07
CVE-2006-6345 [HIGH] CVE-2006-6345: Directory traversal vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 16 and earl Directory traversal vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 16 and earlier, and 7.00 Patchlevel 6 and earlier, allows remote attackers to delete arbitrary files via directory traversal sequences in an HTTP request. NOTE: This information is based upon an initial disclosure. Details will be updated after the grace period has ended. T
nvd
CVE-2006-4133HIGHCVSS 7.5v6.40v6.40_patch_11+2 more2006-08-14
CVE-2006-4133 [HIGH] CVE-2006-4133: Heap-based buffer overflow in SAP Internet Graphics Service (IGS) 6.40 and earlier, and 7.00 and ear Heap-based buffer overflow in SAP Internet Graphics Service (IGS) 6.40 and earlier, and 7.00 and earlier, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via an HTTP request with an ADM:GETLOGFILE command and a long portwatcher argument, which triggers the overflow during error message construction when the _snprintf funct
nvd
CVE-2006-4134MEDIUMCVSS 5.0v6.40v6.40_patch_11+2 more2006-08-14
CVE-2006-4134 [MEDIUM] CVE-2006-4134: Unspecified vulnerability related to a "design flaw" in SAP Internet Graphics Service (IGS) 6.40 and Unspecified vulnerability related to a "design flaw" in SAP Internet Graphics Service (IGS) 6.40 and earlier and 7.00 and earlier allows remote attackers to cause a denial of service (service shutdown) via certain HTTP requests. NOTE: This information is based upon a vague initial disclosure. Details will be updated after the grace period has ended.
nvd