CVE-2021-27625: Input Validation
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method IgsData::freeMemory() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27625?
CVE-2021-27625 has been assigned a high severity rating due to its potential for exploitation by unauthorized attackers.
How do I fix CVE-2021-27625?
To fix CVE-2021-27625, you should apply the latest security patch provided by SAP for your affected versions.
Which versions are affected by CVE-2021-27625?
CVE-2021-27625 affects SAP Internet Graphics Service versions 7.20, 7.20EXT, 7.53, 7.20_EX2, and 7.81.
What type of attack does CVE-2021-27625 facilitate?
CVE-2021-27625 allows an unauthenticated attacker to submit malicious IGS requests over the network.
What does insufficient input validation mean in CVE-2021-27625?
Insufficient input validation in CVE-2021-27625 refers to the system's failure to properly check and filter input data before processing it, leading to vulnerabilities.