CVE-2018-2392

HIGH EXPLOITED NUCLEI

SAP Internet Graphics Server (IGS) XMLCHART XXE

Title source: metasploit

Description

Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.

Exploits (2)

nomisec WORKING POC 1 stars
by Vladimir-Ivanov-Git · infoleak
https://github.com/Vladimir-Ivanov-Git/sap_igs_xxe
metasploit WORKING POC
by Yvan Genuer, Vladimir Ivanov · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/sap/sap_igs_xmlchart_xxe.rb

Nuclei Templates (1)

SAP Internet Graphics Server (IGS) - XML External Entity Injection
HIGHby _generic_human_

Scores

CVSS v3 7.5
EPSS 0.8638
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

VulnCheck KEV 2025-06-07
CWE
CWE-611
Status published
Products (5)
sap/internet_graphics_server 7.20
sap/internet_graphics_server 7.20ext
sap/internet_graphics_server 7.45
sap/internet_graphics_server 7.49
sap/internet_graphics_server 7.53
Published Feb 14, 2018
Tracked Since Feb 18, 2026