File Upload Vulnerability in SAP Internet Graphics Server
CVE-2018-2420
6.5MEDIUM
Summary
The SAP Internet Graphics Server (IGS) is susceptible to a file upload vulnerability due to inadequate validation of uploaded file formats. An attacker can exploit this weakness to upload arbitrary files, which may include malicious scripts. This could lead to unauthorized access to server resources and execution of harmful actions. Organizations using affected versions of SAP IGS must ensure immediate patching and closely monitor their systems for signs of exploitation.
Affected Version(s)
SAP Internet Graphics Server (IGS) 7.20
SAP Internet Graphics Server (IGS) 7.20EXT
SAP Internet Graphics Server (IGS) 7.45
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved