SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CDrawRaster::LoadImageFromMemory() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.
References
| Link | Resource |
|---|---|
| https://launchpad.support.sap.com/#/notes/3021050 | Permissions Required Vendor Advisory |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999 | Vendor Advisory |
| http://seclists.org/fulldisclosure/2021/Oct/31 | Mailing List Patch Third Party Advisory |
| http://packetstormsecurity.com/files/164598/SAP-NetWeaver-ABAP-IGS-Memory-Corruption.html | Patch Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
|
Information
Published : 2021-06-09 14:15
Updated : 2021-11-04 13:20
NVD link : CVE-2021-27622
Mitre link : CVE-2021-27622
JSON object : View
Products Affected
sap
- netweaver_as_internet_graphics_server
CWE
CWE-20
Improper Input Validation
