CVE-2018-2392: XEE
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2392?
The severity of CVE-2018-2392 is high with a severity value of 7.5.
How does SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, and 7.53 validate XML External Entity?
Under certain conditions, SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, and 7.53 fails to validate XML External Entity appropriately, causing the SAP Internet Graphics Server (IGS) to become unavailable.
How can I check if my SAP Internet Graphics Server (IGS) version is affected by CVE-2018-2392?
You can check if your SAP Internet Graphics Server (IGS) version is affected by CVE-2018-2392 by verifying if you are using the versions 7.20, 7.20EXT, 7.45, 7.49, or 7.53.
How do I protect my SAP Internet Graphics Server (IGS) from CVE-2018-2392?
To protect your SAP Internet Graphics Server (IGS) from CVE-2018-2392, you should apply the security patch provided by SAP as mentioned in the SAP Security Patch Day February 2018 blog post and SAP note 2525222.
What is the Common Weakness Enumeration (CWE) for CVE-2018-2392?
The Common Weakness Enumeration (CWE) for CVE-2018-2392 is CWE-611.