CVE-2018-2420: Malicious File Upload
Published May 9, 2018
·Updated
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper file format validation.
Affected Software
5 affected components
SAP Internet Graphics Server=7.20
SAP Internet Graphics Server=7.20ext
SAP Internet Graphics Server=7.45
SAP Internet Graphics Server=7.49
SAP Internet Graphics Server=7.53
Event History
May 9, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-2420.
2
What is the severity rating of CVE-2018-2420?
CVE-2018-2420 has a severity rating of 9.8 (Critical).
3
What is affected by CVE-2018-2420?
SAP Internet Graphics Server (IGS) versions 7.20, 7.20EXT, 7.45, 7.49, and 7.53 are affected by CVE-2018-2420.
4
What is the recommended solution for CVE-2018-2420?
Apply the necessary security patches provided by SAP to fix CVE-2018-2420.
5
Where can I find more information about CVE-2018-2420?
You can find more information about CVE-2018-2420 in the references provided: http://www.securityfocus.com/bid/104108 and https://launchpad.support.sap.com/#/notes/2615635.