SAP security note 2644147, "[CVE-2018-2439] Code Injection Vulnerability in SAP Internet Graphics Server (IGS)", released on July 10, 2018. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
SAP has released Security Note 2644147 addressing a Code Injection vulnerability in the SAP Internet Graphics Server (IGS). This vulnerability allows an attacker to inject and execute malicious code, potentially controlling the behavior of the affected application.
- Unauthorized execution of commands
- Sensitive information disclosure
- Denial of Service
Solution
SAP has provided patches to mitigate this vulnerability. It is crucial to apply the appropriate Support Package Patches for your specific version of SAP IGS. You can download the necessary patches from the SAP Support Package Patches section of the SAP security note.
CVSS
Score 4.7 Vector: AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected components
- BC-FES-IGS (7.20, 7.20EXT, 7.45, 7.49, 7.53)
Full note on SAP: SAP Support Launchpad note 2644147
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
