CVE-2018-2396: Medium severity sap netweaver as internet graphics server vulnerability
Under certain conditions a malicious user can prevent legitimate users from accessing the SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, using IGS Interpreter service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-2396?
CVE-2018-2396 is a vulnerability that allows a malicious user to prevent legitimate users from accessing the SAP Internet Graphics Server (IGS) under certain conditions.
Which versions of SAP Internet Graphics Server (IGS) are affected by CVE-2018-2396?
Versions 7.20, 7.20EXT, 7.45, 7.49, and 7.53 of SAP Internet Graphics Server (IGS) are affected by CVE-2018-2396.
What is the severity of CVE-2018-2396?
CVE-2018-2396 has a severity rating of 6.5 (Medium).
How does CVE-2018-2396 affect SAP Internet Graphics Server (IGS)?
Under certain conditions, CVE-2018-2396 allows a malicious user to prevent legitimate users from accessing the SAP Internet Graphics Server (IGS) by exploiting the IGS Interpreter service.
How can I fix CVE-2018-2396?
To fix CVE-2018-2396, apply the security patch provided by SAP. Refer to the SAP Security Patch Day February 2018 blog post (link: https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/) and SAP note 2525222 (link: https://launchpad.support.sap.com/#/notes/2525222) for more information.