Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2018-2421 Denial of Service in SAP Internet Graphics Server (IGS) Portwatcher, SAP security note 2616599

SAP Note 2616599

SAP security note 2616599, "[CVE-2018-2421] Denial of Service in SAP Internet Graphics Server (IGS) Portwatcher", is a note. Below are the symptom, SAP recommended solution and the affected software components.

Description

Symptom

SAP Internet Graphics Server (IGS) allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

Some well-known impacts of Denial of Service vulnerability are:

  • Long response delays and service interruptions, thus degrading the service quality experienced by legitimate users
  • Direct impact on availability

Solution

The SAP Internet Graphics Server (IGS) performs additional input validation to validate target and filename entries before performing the requested action.

Please download the patch level indicated in the Support Packages and Patches section of this SAP Security Note to apply the security correction.

Reason and prerequisites

The SAP Internet Graphics Server (IGS) Portwatcher is susceptible to a couple of buffer overflows due to insufficient input validation on the target directory and filename input.

CVSS

Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Affected components

  • BC-FES-IGS (7.20, 7.20EXT, 7.45, 7.49, 7.53)

Full note on SAP: SAP Support Launchpad note 2616599

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More