VYPR

Internet Graphics Server

by SAP

CVEs (36)

  • CVE-2021-27625MedJun 9, 2021
    risk 0.38cvss 5.9epss 0.01

    SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method…

  • CVE-2021-27624MedJun 9, 2021
    risk 0.38cvss 5.9epss 0.01

    SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method…

  • CVE-2021-27623MedJun 9, 2021
    risk 0.38cvss 5.9epss 0.01

    SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method…

  • CVE-2021-27622MedJun 9, 2021
    risk 0.38cvss 5.9epss 0.01

    SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method…

  • CVE-2021-27620MedJun 9, 2021
    risk 0.38cvss 5.9epss 0.01

    SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method Ups::AddPart()…

  • CVE-2018-2439MedJul 10, 2018
    risk 0.38cvss 5.9epss 0.02

    The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request validation (for example, where the request is validated for authenticity and validity) and under certain conditions, will process invalid requests. Several areas of the SAP Internet…

  • CVE-2018-2389MedFeb 14, 2018
    risk 0.37cvss 5.7epss 0.01

    Under certain conditions a malicious user can inject log files of SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, hiding important information in the log file.

  • CVE-2018-2423MedMay 9, 2018
    risk 0.35cvss 5.3epss 0.03

    SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

  • CVE-2018-2422MedMay 9, 2018
    risk 0.35cvss 5.3epss 0.02

    SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

  • CVE-2018-2421MedMay 9, 2018
    risk 0.35cvss 5.3epss 0.03

    SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

  • CVE-2007-3613Jul 6, 2007
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in ADM:GETLOGFILE in SAP Internet Graphics Service (IGS) allows remote attackers to inject arbitrary web script or HTML via the PARAMS parameter.

  • CVE-2006-4133Aug 14, 2006
    risk 0.01cvss epss 0.06

    Heap-based buffer overflow in SAP Internet Graphics Service (IGS) 6.40 and earlier, and 7.00 and earlier, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via an HTTP request with an ADM:GETLOGFILE command and a long portwatcher argument,…

  • CVE-2006-6346Dec 7, 2006
    risk 0.00cvss epss 0.03

    Unspecified vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 15 and earlier, and 7.00 Patchlevel 3 and earlier, allows remote attackers to cause a denial of service (service shutdown), obtain sensitive information (configuration files), and conduct certain…

  • CVE-2006-6345Dec 7, 2006
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 16 and earlier, and 7.00 Patchlevel 6 and earlier, allows remote attackers to delete arbitrary files via directory traversal sequences in an HTTP request. NOTE: This information is based…

  • CVE-2006-4134Aug 14, 2006
    risk 0.00cvss epss 0.05

    Unspecified vulnerability related to a "design flaw" in SAP Internet Graphics Service (IGS) 6.40 and earlier and 7.00 and earlier allows remote attackers to cause a denial of service (service shutdown) via certain HTTP requests. NOTE: This information is based upon a vague…

  • CVE-2005-1691Jul 26, 2005
    risk 0.00cvss epss 0.02

    Directory traversal vulnerability in Internet Graphics Server in SAP before 6.40 Patch 11 allows remote attackers to read arbitrary files via ".." sequences in an HTTP GET request.

Page 2 of 2