Memory Corruption Vulnerability in SAP Internet Graphics Service
CVE-2021-27620

5.9MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
9 June 2021

Summary

The SAP Internet Graphics Service is susceptible to a memory corruption vulnerability due to insufficient input validation in the Ups::AddPart() method. An unauthenticated attacker can exploit this flaw after retrieving an existing system state value, allowing them to submit a crafted IGS request over the network. This can lead to internal memory corruption, resulting in a crash of the service and making the system unavailable. During this attack, the attacker cannot access or modify any data within the system.

Affected Version(s)

SAP Internet Graphics Service < 7.20 < 7.20

SAP Internet Graphics Service < 7.20EXT < 7.20EXT

SAP Internet Graphics Service < 7.53 < 7.53

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.