Sap Se Sap Internet Graphics Server vulnerabilities
17 known vulnerabilities affecting sap_se/sap_internet_graphics_server.
Total CVEs
17
CISA KEV
0
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL1HIGH6MEDIUM10
Vulnerabilities
Page 1 of 1
CVE-2018-2392P1HIGHCVSS 7.5ExploitedPoCv7.20v7.20EXT+3 more2018-02-14
CVE-2018-2392 [HIGH] CWE-611 CVE-2018-2392: Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails t
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
nvd
CVE-2018-2393P3HIGHCVSS 7.5PoCv7.20v7.20EXT+3 more2018-02-14
CVE-2018-2393 [HIGH] CWE-611 CVE-2018-2393: Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails t
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
nvd
CVE-2018-2420P3CRITICALCVSS 9.8v7.20v7.20EXT+3 more2018-05-09
CVE-2018-2420 [CRITICAL] CWE-434 CVE-2018-2420: SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload an
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper file format validation.
nvd
CVE-2018-2395P3HIGHCVSS 8.8v7.20v7.20EXT+3 more2018-02-14
CVE-2018-2395 [HIGH] CVE-2018-2395: Under certain conditions a malicious user may retrieve information on SAP Internet Graphic Server (I
Under certain conditions a malicious user may retrieve information on SAP Internet Graphic Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, overwrite existing image or corrupt other type of files.
nvd
CVE-2018-2423P3HIGHCVSS 7.5v7.20v7.20EXT+3 more2018-05-09
CVE-2018-2423 [HIGH] CVE-2018-2423: SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
nvd
CVE-2018-2421P3HIGHCVSS 7.5v7.20v7.20EXT+3 more2018-05-09
CVE-2018-2421 [HIGH] CVE-2018-2421: SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker
SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
nvd
CVE-2018-2422P3HIGHCVSS 7.5v7.20v7.20EXT+3 more2018-05-09
CVE-2018-2422 [HIGH] CVE-2018-2422: SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker
SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
nvd
CVE-2018-2382P4MEDIUMCVSS 6.5v7.20v7.20EXT+3 more2018-02-14
CVE-2018-2382 [MEDIUM] CVE-2018-2382: A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a
A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to store graphics in a controlled area and as such gain information from system area, which is not available to the user otherwise.
nvd
CVE-2018-2394P4MEDIUMCVSS 6.5v7.20v7.20EXT+3 more2018-02-14
CVE-2018-2394 [MEDIUM] CVE-2018-2394: Under certain conditions an unauthenticated malicious user can prevent legitimate users from accessi
Under certain conditions an unauthenticated malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, services and/or system files.
nvd
CVE-2018-2386P4MEDIUMCVSS 6.5v7.20v7.20EXT+3 more2018-02-14
CVE-2018-2386 [MEDIUM] CWE-119 CVE-2018-2386: Under certain conditions a malicious user provoking an out of bounds buffer overflow can prevent leg
Under certain conditions a malicious user provoking an out of bounds buffer overflow can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53.
nvd
CVE-2018-2387P4MEDIUMCVSS 6.5v7.20v7.20EXT+3 more2018-02-14
CVE-2018-2387 [MEDIUM] CVE-2018-2387: A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a
A vulnerability in the SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, could allow a malicious user to obtain information on ports, which is not available to the user otherwise.
nvd
CVE-2018-2385P4MEDIUMCVSS 6.5v7.20v7.20EXT+3 more2018-02-14
CVE-2018-2385 [MEDIUM] CWE-369 CVE-2018-2385: Under certain conditions a malicious user provoking a divide by zero crash can prevent legitimate us
Under certain conditions a malicious user provoking a divide by zero crash can prevent legitimate users from accessing the SAP Internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, and its services.
nvd
CVE-2018-2396P4MEDIUMCVSS 6.5v7.20v7.20EXT+3 more2018-02-14
CVE-2018-2396 [MEDIUM] CVE-2018-2396: Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Intern
Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, using IGS Interpreter service.
nvd
CVE-2018-2384P4MEDIUMCVSS 6.5v7.20v7.20EXT+3 more2018-02-14
CVE-2018-2384 [MEDIUM] CWE-476 CVE-2018-2384: Under certain conditions a malicious user provoking a Null Pointer dereference can prevent legitimat
Under certain conditions a malicious user provoking a Null Pointer dereference can prevent legitimate users from accessing the SAP Internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, and its services.
nvd
CVE-2018-2389P4MEDIUMCVSS 5.7v7.20v7.20EXT+3 more2018-02-14
CVE-2018-2389 [MEDIUM] CWE-116 CVE-2018-2389: Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS)
Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, hiding important information in the log file.
nvd
CVE-2018-2388P4MEDIUMCVSS 6.1v7.20v7.20EXT+3 more2018-02-14
CVE-2018-2388 [MEDIUM] CWE-79 CVE-2018-2388: Stored cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49
Stored cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.
nvd
CVE-2018-2383P4MEDIUMCVSS 6.1v7.20v7.20EXT+3 more2018-02-14
CVE-2018-2383 [MEDIUM] CWE-79 CVE-2018-2383: Reflected cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7
Reflected cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.
nvd