First published: Thu Dec 07 2006(Updated: )
Directory traversal vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 16 and earlier, and 7.00 Patchlevel 6 and earlier, allows remote attackers to delete arbitrary files via directory traversal sequences in an HTTP request. NOTE: This information is based upon an initial disclosure. Details will be updated after the grace period has ended. This issue is different from CVE-2006-4133 and CVE-2006-4134.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Internet Graphics Server | <=6.40_patch_16 | |
SAP Internet Graphics Server | <=7.00_patch_3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-6345 has been classified as a medium severity vulnerability due to its potential for misuse by attackers to delete arbitrary files.
To fix CVE-2006-6345, update your SAP Internet Graphics Service to version 6.40 Patchlevel 17 or later, or version 7.00 Patchlevel 7 or later.
CVE-2006-6345 affects SAP Internet Graphics Service versions 6.40 Patchlevel 16 and earlier, as well as versions 7.00 Patchlevel 6 and earlier.
CVE-2006-6345 allows remote attackers to perform directory traversal attacks, potentially leading to unauthorized file deletion.
A recommended temporary workaround for CVE-2006-6345 is to restrict access to the affected service until a patch can be applied.