CVE-2021-27620: Input Validation
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method Ups::AddPart() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27620?
CVE-2021-27620 has a medium severity rating due to the potential for unauthenticated access and exploitation of the vulnerability.
How do I fix CVE-2021-27620?
To fix CVE-2021-27620, apply the latest security patches provided by SAP for the affected versions of the Internet Graphics Service.
What versions are affected by CVE-2021-27620?
CVE-2021-27620 affects SAP Internet Graphics Service versions 7.20, 7.20EXT, 7.53, 7.20_EX2, and 7.81.
What type of vulnerability is CVE-2021-27620?
CVE-2021-27620 is classified as an input validation vulnerability that allows for remote exploitation.
Who can exploit CVE-2021-27620?
CVE-2021-27620 can be exploited by unauthenticated attackers who can send malicious requests over the network.