Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
References
Link | Resource |
---|---|
https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/ | Vendor Advisory |
https://launchpad.support.sap.com/#/notes/2525222 | Permissions Required Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2018-02-14 12:29
Updated : 2018-03-01 15:39
NVD link : CVE-2018-2393
Mitre link : CVE-2018-2393
CVE.ORG link : CVE-2018-2393
JSON object : View
Products Affected
sap
- internet_graphics_server
CWE
CWE-611
Improper Restriction of XML External Entity Reference