Memory Corruption Vulnerability in SAP Internet Graphics Service
CVE-2021-27625
5.9MEDIUM
Summary
SAP Internet Graphics Service is susceptible to an unauthenticated attack that may exploit insufficient input validation. By retrieving an existing system state value, an attacker can send a crafted IGS request over a network. This action results in a memory corruption error when the IgsData::freeMemory() method is triggered, ultimately causing the system to crash and become unavailable. Notably, this vulnerability does not permit data viewing or modification within the system.
Affected Version(s)
SAP Internet Graphics Service < 7.20 < 7.20
SAP Internet Graphics Service < 7.20EXT < 7.20EXT
SAP Internet Graphics Service < 7.53 < 7.53
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved