First published: Wed Jun 09 2021(Updated: )
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method IgsData::freeMemory() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Netweaver As Internet Graphics Server | =7.20 | |
Sap Netweaver As Internet Graphics Server | =7.20ex2 | |
Sap Netweaver As Internet Graphics Server | =7.20ext | |
Sap Netweaver As Internet Graphics Server | =7.53 | |
Sap Netweaver As Internet Graphics Server | =7.81 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27625 has been assigned a high severity rating due to its potential for exploitation by unauthorized attackers.
To fix CVE-2021-27625, you should apply the latest security patch provided by SAP for your affected versions.
CVE-2021-27625 affects SAP Internet Graphics Service versions 7.20, 7.20EXT, 7.53, 7.20_EX2, and 7.81.
CVE-2021-27625 allows an unauthenticated attacker to submit malicious IGS requests over the network.
Insufficient input validation in CVE-2021-27625 refers to the system's failure to properly check and filter input data before processing it, leading to vulnerabilities.