CVE-2018-2420

MEDIUM

SAP Internet Graphics Server - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper file format validation.

References (3)

Core 3
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2615635
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/104108

Scores

CVSS v3 6.5
EPSS 0.0062
EPSS Percentile 70.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

Details

CWE
CWE-434
Status published
Products (5)
sap/internet_graphics_server 7.20
sap/internet_graphics_server 7.20ext
sap/internet_graphics_server 7.45
sap/internet_graphics_server 7.49
sap/internet_graphics_server 7.53
Published May 09, 2018
Tracked Since Feb 18, 2026