Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-2392


Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.


Published

2018-02-14T12:29:01.453

Last Modified

2024-11-21T04:03:44.133

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sap internet_graphics_server 7.20 Yes
Application sap internet_graphics_server 7.20ext Yes
Application sap internet_graphics_server 7.45 Yes
Application sap internet_graphics_server 7.49 Yes
Application sap internet_graphics_server 7.53 Yes

References