Memory Corruption Vulnerability in SAP Internet Graphics Service
CVE-2021-27627
5.9MEDIUM
Summary
The SAP Internet Graphics Service has a vulnerability that allows an unauthenticated attacker to exploit insufficient input validation in the ChartInterpreter::DoIt() method. By making a crafted request after obtaining a system state value, the attacker can trigger internal memory corruption, leading to a system crash and negating availability. This flaw does not permit data viewing or modification.
Affected Version(s)
SAP Internet Graphics Service < 7.20 < 7.20
SAP Internet Graphics Service < 7.20EXT < 7.20EXT
SAP Internet Graphics Service < 7.53 < 7.53
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved