SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method IgsData::freeMemory() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/3021050 | Permissions Required Vendor Advisory |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999 | Broken Link Vendor Advisory |
https://launchpad.support.sap.com/#/notes/3021050 | Permissions Required Vendor Advisory |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999 | Broken Link Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:58
Type | Values Removed | Values Added |
---|---|---|
References | () https://launchpad.support.sap.com/#/notes/3021050 - Permissions Required, Vendor Advisory | |
References | () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999 - Broken Link, Vendor Advisory |
31 Oct 2022, 14:46
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999 - Broken Link, Vendor Advisory |
17 Oct 2022, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
07 Oct 2022, 18:52
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-787 |
04 Nov 2021, 14:26
Type | Values Removed | Values Added |
---|---|---|
References | (FULLDISC) http://seclists.org/fulldisclosure/2021/Oct/31 - Mailing List, Patch, Third Party Advisory | |
References | (MISC) http://packetstormsecurity.com/files/164598/SAP-NetWeaver-ABAP-IGS-Memory-Corruption.html - Patch, Third Party Advisory, VDB Entry |
22 Oct 2021, 18:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
22 Oct 2021, 16:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
14 Jun 2021, 20:20
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-20 | |
References | (MISC) https://launchpad.support.sap.com/#/notes/3021050 - Permissions Required, Vendor Advisory | |
References | (MISC) https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999 - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : 4.3
v3 : 5.9 |
CPE | cpe:2.3:a:sap:netweaver_as_internet_graphics_server:7.20ex2:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver_as_internet_graphics_server:7.53:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver_as_internet_graphics_server:7.81:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver_as_internet_graphics_server:7.20ext:*:*:*:*:*:*:* cpe:2.3:a:sap:netweaver_as_internet_graphics_server:7.20:*:*:*:*:*:*:* |
09 Jun 2021, 15:04
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2021-06-09 14:15
Updated : 2024-11-21 05:58
NVD link : CVE-2021-27625
Mitre link : CVE-2021-27625
CVE.ORG link : CVE-2021-27625
JSON object : View
Products Affected
sap
- netweaver_as_internet_graphics_server
CWE
CWE-787
Out-of-bounds Write