CVE-2018-2392
HIGH EXPLOITED NUCLEISAP Internet Graphics Server (IGS) XMLCHART XXE
Title source: metasploitDescription
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
Exploits (2)
nomisec
WORKING POC
1 stars
by Vladimir-Ivanov-Git · infoleak
https://github.com/Vladimir-Ivanov-Git/sap_igs_xxe
metasploit
WORKING POC
by Yvan Genuer, Vladimir Ivanov · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/admin/sap/sap_igs_xmlchart_xxe.rb
Nuclei Templates (1)
SAP Internet Graphics Server (IGS) - XML External Entity Injection
HIGHby _generic_human_
Scores
CVSS v3
7.5
EPSS
0.8638
EPSS Percentile
99.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
VulnCheck KEV
2025-06-07
CWE
CWE-611
Status
published
Products (5)
sap/internet_graphics_server
7.20
sap/internet_graphics_server
7.20ext
sap/internet_graphics_server
7.45
sap/internet_graphics_server
7.49
sap/internet_graphics_server
7.53
Published
Feb 14, 2018
Tracked Since
Feb 18, 2026