First published: Wed Feb 14 2018(Updated: )
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP internet Graphics Server | =7.20 | |
SAP internet Graphics Server | =7.20ext | |
SAP internet Graphics Server | =7.45 | |
SAP internet Graphics Server | =7.49 | |
SAP internet Graphics Server | =7.53 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-2392 is high with a severity value of 7.5.
Under certain conditions, SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, and 7.53 fails to validate XML External Entity appropriately, causing the SAP Internet Graphics Server (IGS) to become unavailable.
You can check if your SAP Internet Graphics Server (IGS) version is affected by CVE-2018-2392 by verifying if you are using the versions 7.20, 7.20EXT, 7.45, 7.49, or 7.53.
To protect your SAP Internet Graphics Server (IGS) from CVE-2018-2392, you should apply the security patch provided by SAP as mentioned in the SAP Security Patch Day February 2018 blog post and SAP note 2525222.
The Common Weakness Enumeration (CWE) for CVE-2018-2392 is CWE-611.