CVE-2018-2420

6.5MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
9 May 2018

Summary

SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper file format validation.

Affected Version(s)

SAP Internet Graphics Server (IGS) 7.20

SAP Internet Graphics Server (IGS) 7.20EXT

SAP Internet Graphics Server (IGS) 7.45

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.