CVE-2021-27626: Input Validation
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CMiniXMLParser::Parse() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27626?
CVE-2021-27626 is classified as a high severity vulnerability due to its potential for unauthenticated remote code execution.
How do I fix CVE-2021-27626?
To remediate CVE-2021-27626, you should apply the latest security patches provided by SAP for the affected versions of the Internet Graphics Service.
What systems are affected by CVE-2021-27626?
CVE-2021-27626 affects SAP NetWeaver AS Internet Graphics Server versions 7.20, 7.20ex2, 7.20ext, 7.53, and 7.81.
What type of attacks can exploit CVE-2021-27626?
An attacker can exploit CVE-2021-27626 to perform remote code execution through malicious IGS requests due to insufficient input validation.
Is CVE-2021-27626 unique to a specific SAP service?
Yes, CVE-2021-27626 specifically impacts the SAP Internet Graphics Service within the NetWeaver architecture.