CVE-2018-2420 describes a critical file upload vulnerability in multiple versions of SAP Internet Graphics Server (IGS), including 7.20, 7.20EXT, 7.45, 7.49, and 7.53. This flaw, rated 9.8 CVSSv3.0 (Critical), allows an unauthenticated attacker to upload arbitrary files, including malicious scripts, due to a lack of proper file format validation. Such an exploit could lead to complete compromise of the affected system (Confidentiality, Integrity, and Availability). While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has received some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.20CPE matchmatch criteria | cpe:2.3:a:sap:internet_graphics_server:7.20:*:*:*:*:*:*:* | ||
7.20extCPE matchmatch criteria | cpe:2.3:a:sap:internet_graphics_server:7.20ext:*:*:*:*:*:*:* | ||
7.45CPE matchmatch criteria | cpe:2.3:a:sap:internet_graphics_server:7.45:*:*:*:*:*:*:* | ||
7.49CPE matchmatch criteria | cpe:2.3:a:sap:internet_graphics_server:7.49:*:*:*:*:*:*:* | ||
7.53CPE matchmatch criteria | cpe:2.3:a:sap:internet_graphics_server:7.53:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.