CVE-2018-2437: Critical severity sap netweaver as internet graphics server vulnerability
The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to externally trigger IGS command executions which can lead to: disclosure of information and malicious file insertion or modification.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this SAP Internet Graphics Service vulnerability?
The vulnerability ID is CVE-2018-2437.
What is the severity level of CVE-2018-2437?
The severity level of CVE-2018-2437 is critical with a CVSS score of 9.1.
How can an attacker exploit CVE-2018-2437?
An attacker can externally trigger IGS command executions, leading to disclosure of information and malicious file insertion or modification.
Which versions of SAP Internet Graphics Service are affected by CVE-2018-2437?
Versions 7.20, 7.20EXT, 7.45, 7.49, and 7.53 of SAP Internet Graphics Service are affected.
Where can I find more information about CVE-2018-2437?
You can find more information about CVE-2018-2437 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/104705), [SAP Note 2644227](https://launchpad.support.sap.com/#/notes/2644227), [SAP Community Network](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000).