Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2423 Denial of Service in SAP Internet Graphic Server (IGS) RFC listener, SAP security note 2620744

SAP Note 2620744

SAP security note 2620744, "[CVE-2018-2423] Denial of Service in SAP Internet Graphic Server (IGS) RFC listener", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The SAP Internet Graphic Server (IGS) HTTP and RFC listener has a Denial of Service (DoS) vulnerability identified as CVE-2018-2423. This vulnerability allows an attacker to prevent legitimate users from accessing the service by either crashing or flooding it. Consequences of this vulnerability include:

  • Long response delays and service interruptions, degrading service quality for legitimate users.
  • Direct impact on the availability of the service.

Solution

To address this vulnerability, additional input validation has been implemented to validate HTTP and RFC requests. It is recommended to upgrade to the IGS patch levels specified in the Support Packages and Patches section of this SAP Note 2620744 to apply the necessary security corrections.

CVSS

Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References

Affected components

  • BC-FES-IGS (7.20, 7.20EXT, 7.45, 7.49, 7.53)

Full note on SAP: SAP Support Launchpad note 2620744

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More