Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2422 Denial of Service in SAP Internet Graphic Server (IGS) Portwatcher, SAP security note 2617553

SAP Note 2617553

SAP security note 2617553, "[CVE-2018-2422] Denial of Service in SAP Internet Graphic Server (IGS) Portwatcher", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

The SAP Internet Graphic Server (IGS) allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

Some well-known impacts of denial-of-service vulnerabilities are:

  • Long response delays and service interruptions, degrading the service quality experienced by legitimate users
  • Direct impact on availability

Solution

Additional input validation was added to validate IMGCONV requests to patch the vulnerability. Please download the SAP Internet Graphic Server (IGS) patch level as indicated in the Support Packages and Patches section of this SAP Security Note to apply the security correction.

Reason and prerequisites

Due to insufficient input validation in the IGS IMGCONV interpreter, the IGS portwatcher is susceptible to a denial-of-service vulnerability.

CVSS

Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

References

  • CVE Details: CVE-2018-2422

Affected components

  • BC-FES-IGS (7.20, 7.20EXT, 7.45, 7.49, 7.53)

Full note on SAP: SAP Support Launchpad note 2617553

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More