Insufficient Input Validation in SAP Internet Graphics Service
CVE-2021-27624
5.9MEDIUM
What is CVE-2021-27624?
The SAP Internet Graphics Service versions 7.20, 7.20EXT, 7.53, 7.20_EX2, and 7.81 exhibit a vulnerability that allows an attacker to exploit insufficient input validation. By retrieving an existing system state value, the attacker can submit a malicious IGS request over the network, leading to an internal memory corruption error. This results in a crash of the system, making it unavailable for legitimate users while preventing any data from being accessed or modified.
Affected Version(s)
SAP Internet Graphics Service < 7.20 < 7.20
SAP Internet Graphics Service < 7.20EXT < 7.20EXT
SAP Internet Graphics Service < 7.53 < 7.53