Internet Graphics Server

Vendor:

First CVE: Aug 14, 2006 · Active for 19 years

28
Total CVEs
More Total CVEs than 96% of tracked products
9.3
Avg CVEs / Year
Higher CVE frequency than 95% of tracked products
7.1
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Internet Graphics Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 14, 2006
19 years ago
Most Recent CVE
Aug 14, 2018
2,901 days ago

CVE Severity & Scoring

Internet Graphics Server28 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network23 (82.1%)
Unknown5 (17.9%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low22 (78.6%)
High1 (3.6%)
Unknown5 (17.9%)
User Interaction
None19 (67.9%)
Unknown5 (17.9%)
Required4 (14.3%)
Privileges Required
Low11 (39.3%)
High0 (0.0%)
None12 (42.9%)
Unknown5 (17.9%)

Top CVEs

Signals from CVEs in this product scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics S
Feb 14, 20187.565NOYES
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics S
Feb 14, 20187.543NOYES
The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to externally trigger IGS command executions which can lead to: disclosure of informati
Jul 10, 20189.129NONO
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper file format validation.
May 9, 20189.828NONO
In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP ana
Aug 14, 20188.826NONO
Under certain conditions a malicious user may retrieve information on SAP Internet Graphic Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, overwrite existing image or corrupt other
Feb 14, 20188.826NONO
Unspecified vulnerability in SAP Internet Graphics Service (IGS) 6.40 Patchlevel 15 and earlier, and 7.00 Patchlevel 3 and earlier, allows remote attackers to cause a denial of ser
Dec 7, 200610.025NONO
The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has several denial-of-service vulnerabilities that allow an attacker to prevent legitimate users from acces
Jul 10, 20187.524NONO
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, HTTP and RFC listener allows an attacker to prevent legitimate users from accessing a service, either by crashi
May 9, 20187.523NONO
SAP Internet Graphics Server (IGS) Portwatcher, 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to prevent legitimate users from accessing a service, either by crashing or floo
May 9, 20187.522NONO

Exploit Exposure

Signals from CVEs in this product scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
7.1% of CVEs· 97th percentile
Nuclei
1 CVE
3.6% of CVEs· 97th percentile
ExploitDB
1 CVE
3.6% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (28 CVEs).

Media Mentions

Signals from CVEs in this product scope (28 CVEs).

Top CNAs Publishing CVEs For Internet Graphics Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.53237.13.8%02
7.49237.13.8%02
7.45237.13.8%02
7.20ext237.13.8%02
7.20237.13.8%02
7.00_patch_335.64.4%01
7.00_patch_214.32.4%01
7.00_patch_114.32.4%01
6.40_patch_1535.64.4%01
6.40_patch_1414.32.4%01
6.40_patch_1314.32.4%01
6.40_patch_1214.32.4%01
6.40_patch_1135.64.4%01
6.4035.64.4%01