CVE-2021-27623

S

AP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CXmlUtility::CheckLength() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified.

References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:netweaver_as_internet_graphics_server:7.20:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_internet_graphics_server:7.20ex2:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_internet_graphics_server:7.20ext:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_internet_graphics_server:7.53:*:*:*:*:*:*:*
cpe:2.3:a:sap:netweaver_as_internet_graphics_server:7.81:*:*:*:*:*:*:*

History

21 Nov 2024, 05:58

Type Values Removed Values Added
References () https://launchpad.support.sap.com/#/notes/3021050 - Permissions Required, Vendor Advisory () https://launchpad.support.sap.com/#/notes/3021050 - Permissions Required, Vendor Advisory
References () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999 - Broken Link, Vendor Advisory () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=578125999 - Broken Link, Vendor Advisory

Information

Published : 2021-06-09 14:15

Updated : 2024-11-21 05:58


NVD link : CVE-2021-27623

Mitre link : CVE-2021-27623

CVE.ORG link : CVE-2021-27623


JSON object : View

CWE
CWE-787

Out-of-bounds Write