First published: Wed Jun 09 2021(Updated: )
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method ChartInterpreter::DoIt() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Netweaver As Internet Graphics Server | =7.20 | |
Sap Netweaver As Internet Graphics Server | =7.20ex2 | |
Sap Netweaver As Internet Graphics Server | =7.20ext | |
Sap Netweaver As Internet Graphics Server | =7.53 | |
Sap Netweaver As Internet Graphics Server | =7.81 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-27627 is medium (5.9).
CVE-2021-27627 affects SAP Internet Graphics Service versions 7.20, 7.20EXT, 7.53, 7.20_EX2, and 7.81.
CVE-2021-27627 allows an unauthenticated attacker to submit a malicious IGS request over a network, leading to potential information disclosure or denial of service.
Apply the necessary patches or updates provided by SAP to fix CVE-2021-27627.
You can find more information about CVE-2021-27627 in the following references: [SAP Note 3021050](https://launchpad.support.sap.com/#/notes/3021050) and [SAP Wiki](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999).