CVE-2021-27626

5.9MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
9 June 2021

Summary

SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CMiniXMLParser::Parse() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.

Affected Version(s)

SAP Internet Graphics Service < 7.20 < 7.20

SAP Internet Graphics Service < 7.20EXT < 7.20EXT

SAP Internet Graphics Service < 7.53 < 7.53

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.