CVE-2018-2437
9.1
CRITICAL · CVSS 3.0 · EPSS 3.3% (pctl 88)
In your normal cycle
Critical by CVSS (9.1), but no sign of active exploitation.
Description
The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to externally trigger IGS command executions which can lead to: disclosure of information and malicious file insertion or modification.
Scoring
| CVSS | 9.1 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 3.26% — more likely to be exploited than 88% of all CVEs |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2018-07-10 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| sap | internet graphics server |
References
- http://www.securityfocus.com/bid/104705
- https://launchpad.support.sap.com/#/notes/2644227
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000
- http://www.securityfocus.com/bid/104705
- https://launchpad.support.sap.com/#/notes/2644227
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000
→ the Explorer · watch your stack · NVD