Memory Corruption Vulnerability in SAP Internet Graphics Service
CVE-2021-27623
5.9MEDIUM
What is CVE-2021-27623?
The vulnerability in SAP Internet Graphics Service allows an unauthenticated attacker to exploit insufficient input validation in the CXmlUtility::CheckLength() method, leading to a memory corruption error. By submitting a crafted IGS request over the network after retrieving an existing system state value, the attacker can cause the system to crash, resulting in downtime and unavailability. This issue does not allow for data viewing or modification within the system.
Affected Version(s)
SAP Internet Graphics Service < 7.20 < 7.20
SAP Internet Graphics Service < 7.20EXT < 7.20EXT
SAP Internet Graphics Service < 7.53 < 7.53