CVE-2018-2394: Medium severity sap netweaver as internet graphics server vulnerability
Under certain conditions an unauthenticated malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, services and/or system files.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-2394?
CVE-2018-2394 is a vulnerability that allows an unauthenticated malicious user to prevent legitimate users from accessing the SAP Internet Graphics Server (IGS) services and/or system files.
How does CVE-2018-2394 affect SAP Internet Graphics Server (IGS)?
Under certain conditions, CVE-2018-2394 affects SAP Internet Graphics Server (IGS) versions 7.20, 7.20EXT, 7.45, 7.49, and 7.53.
What is the severity of CVE-2018-2394?
The severity of CVE-2018-2394 is medium, with a CVSS score of 6.5.
How can an unauthenticated malicious user exploit CVE-2018-2394?
By exploiting CVE-2018-2394, an unauthenticated malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS) services and/or system files.
Where can I find more information about CVE-2018-2394?
You can find more information about CVE-2018-2394 on the SAP Security Patch Day February 2018 blog post and the SAP note 2525222.