Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Sap Subscribe
Filtered by product Internet Graphics Server
Total 28 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-2439 1 Sap 1 Internet Graphics Server 2018-09-12 4.3 MEDIUM 5.9 MEDIUM
The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request validation (for example, where the request is validated for authenticity and validity) and under certain conditions, will process invalid requests. Several areas of the SAP Internet Graphics Server (IGS) did not require sufficient input validation. Namely, the SAP Internet Graphics Server (IGS) HTTP and RFC listener, SAP Internet Graphics Server (IGS) portwatcher when registering a portwatcher to the multiplexer and the SAP Internet Graphics Server (IGS) multiplexer had insufficient input validation and thus allowing a malformed data packet to cause a crash.
CVE-2018-2392 1 Sap 1 Internet Graphics Server 2018-03-01 5.0 MEDIUM 7.5 HIGH
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
CVE-2018-2393 1 Sap 1 Internet Graphics Server 2018-03-01 5.0 MEDIUM 7.5 HIGH
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
CVE-2018-2386 1 Sap 1 Internet Graphics Server 2018-02-27 4.0 MEDIUM 6.5 MEDIUM
Under certain conditions a malicious user provoking an out of bounds buffer overflow can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53.
CVE-2018-2385 1 Sap 1 Internet Graphics Server 2018-02-27 4.0 MEDIUM 6.5 MEDIUM
Under certain conditions a malicious user provoking a divide by zero crash can prevent legitimate users from accessing the SAP Internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, and its services.
CVE-2018-2384 1 Sap 1 Internet Graphics Server 2018-02-27 4.0 MEDIUM 6.5 MEDIUM
Under certain conditions a malicious user provoking a Null Pointer dereference can prevent legitimate users from accessing the SAP Internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, and its services.
CVE-2018-2383 1 Sap 1 Internet Graphics Server 2018-02-27 4.3 MEDIUM 6.1 MEDIUM
Reflected cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.
CVE-2018-2388 1 Sap 1 Internet Graphics Server 2018-02-27 4.3 MEDIUM 6.1 MEDIUM
Stored cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.