Vulnerability Description
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper file format validation.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Internet Graphics Server | 7.20 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/104108Third Party AdvisoryVDB Entry
- https://blogs.sap.com/2018/05/08/sap-security-patch-day-may-2018/Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2615635Permissions RequiredVendor Advisory
- http://www.securityfocus.com/bid/104108Third Party AdvisoryVDB Entry
- https://blogs.sap.com/2018/05/08/sap-security-patch-day-may-2018/Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2615635Permissions RequiredVendor Advisory
FAQ
What is CVE-2018-2420?
CVE-2018-2420 is a vulnerability with a CVSS score of 6.5 (MEDIUM). SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper file format validation.
How severe is CVE-2018-2420?
CVE-2018-2420 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-2420?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Internet Graphics Server.