SAP security note 2620744, "[CVE-2018-2423] Denial of Service in SAP Internet Graphic Server (IGS) RFC listener", is a note. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
The SAP Internet Graphic Server (IGS) HTTP and RFC listener has a Denial of Service (DoS) vulnerability identified as CVE-2018-2423. This vulnerability allows an attacker to prevent legitimate users from accessing the service by either crashing or flooding it. Consequences of this vulnerability include:
- Long response delays and service interruptions, degrading service quality for legitimate users.
- Direct impact on the availability of the service.
Solution
To address this vulnerability, additional input validation has been implemented to validate HTTP and RFC requests. It is recommended to upgrade to the IGS patch levels specified in the Support Packages and Patches section of this SAP Note 2620744 to apply the necessary security corrections.
CVSS
Score 5.3 Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
References
- SAP Note 2620744
- CVE-2018-2423 Details
Affected components
- BC-FES-IGS (7.20, 7.20EXT, 7.45, 7.49, 7.53)
Full note on SAP: SAP Support Launchpad note 2620744
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
