First published: Wed May 09 2018(Updated: )
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP internet Graphics Server | =7.20 | |
SAP internet Graphics Server | =7.20ext | |
SAP internet Graphics Server | =7.45 | |
SAP internet Graphics Server | =7.49 | |
SAP internet Graphics Server | =7.53 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2423 is a vulnerability in SAP Internet Graphics Server (IGS) versions 7.20, 7.20EXT, 7.45, 7.49, and 7.53 that allows an attacker to prevent legitimate users from accessing a service through crashing or flooding the service.
CVE-2018-2423 has a severity rating of 7.5 (high).
CVE-2018-2423 affects SAP Internet Graphics Server versions 7.20, 7.20EXT, 7.45, 7.49, and 7.53.
An attacker can exploit CVE-2018-2423 by crashing or flooding the SAP Internet Graphics Server (IGS) HTTP or RFC listener, which prevents legitimate users from accessing the service.
You can find more information about CVE-2018-2423 in the following references: [SecurityFocus](http://www.securityfocus.com/bid/104109), [SAP Security Patch Day](https://blogs.sap.com/2018/05/08/sap-security-patch-day-may-2018/), [SAP Note](https://launchpad.support.sap.com/#/notes/2620744).