CVE-2018-2389: Medium severity sap netweaver as internet graphics server vulnerability
Published Feb 14, 2018
·Updated
Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, hiding important information in the log file.
Affected Software
5 affected components
SAP Internet Graphics Server=7.20
SAP Internet Graphics Server=7.20ext
SAP Internet Graphics Server=7.45
SAP Internet Graphics Server=7.49
SAP Internet Graphics Server=7.53
Event History
Feb 14, 2018
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2018-2389.
2
What is the severity of CVE-2018-2389?
The severity of CVE-2018-2389 is medium with a severity value of 5.7.
3
Which version of SAP Internet Graphics Server is affected by CVE-2018-2389?
SAP Internet Graphics Server versions 7.20, 7.20EXT, 7.45, 7.49, and 7.53 are affected by CVE-2018-2389.
4
What can a malicious user do with CVE-2018-2389?
Under certain conditions, a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, hiding important information in the log file.
5
How can I fix CVE-2018-2389?
To fix CVE-2018-2389, it is recommended to apply the necessary security patches provided by SAP.