CVE-2021-27627: Input Validation
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method ChartInterpreter::DoIt() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27627?
The severity of CVE-2021-27627 is medium (5.9).
How does CVE-2021-27627 affect SAP Internet Graphics Service?
CVE-2021-27627 affects SAP Internet Graphics Service versions 7.20, 7.20EXT, 7.53, 7.20_EX2, and 7.81.
What is the impact of CVE-2021-27627?
CVE-2021-27627 allows an unauthenticated attacker to submit a malicious IGS request over a network, leading to potential information disclosure or denial of service.
How can I fix CVE-2021-27627?
Apply the necessary patches or updates provided by SAP to fix CVE-2021-27627.
Where can I find more information about CVE-2021-27627?
You can find more information about CVE-2021-27627 in the following references: [SAP Note 3021050](https://launchpad.support.sap.com/#/notes/3021050) and [SAP Wiki](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999).