CVE-2006-6345: High severity sap internet graphics server vulnerability
Directory traversal vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 16 and earlier, and 7.00 Patchlevel 6 and earlier, allows remote attackers to delete arbitrary files via directory traversal sequences in an HTTP request. NOTE: This information is based upon an initial disclosure. Details will be updated after the grace period has ended. This issue is different from CVE-2006-4133 and CVE-2006-4134.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6345?
CVE-2006-6345 has been classified as a medium severity vulnerability due to its potential for misuse by attackers to delete arbitrary files.
How do I fix CVE-2006-6345?
To fix CVE-2006-6345, update your SAP Internet Graphics Service to version 6.40 Patchlevel 17 or later, or version 7.00 Patchlevel 7 or later.
What software is affected by CVE-2006-6345?
CVE-2006-6345 affects SAP Internet Graphics Service versions 6.40 Patchlevel 16 and earlier, as well as versions 7.00 Patchlevel 6 and earlier.
What types of attacks can be executed via CVE-2006-6345?
CVE-2006-6345 allows remote attackers to perform directory traversal attacks, potentially leading to unauthorized file deletion.
Is there a workaround for CVE-2006-6345?
A recommended temporary workaround for CVE-2006-6345 is to restrict access to the affected service until a patch can be applied.