SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-27626

SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in…

MEDIUM 5.9EPSS 1.21%

Does this matter?

Lower severity and a low EPSS score (1.21%). Track it; it rarely justifies an emergency change on its own.

Description

SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CMiniXMLParser::Parse() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
1.21% probability · 67th percentile
CISA KEV
Not listed
Weakness
CWE-787
Affected
sap/netweaver as internet graphics server
Source
cna@sap.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.