CVE-2018-2437
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 3.3%
exploitation probability
3.3%top 13% of all CVEs
observed exploitation
nono source reports it
In short
SAP Internet Graphics Service has a vulnerability that allows attackers to remotely trigger commands on the server, potentially exposing sensitive information or modifying files without authorization.
Technical detail
CVE-2018-2437 in SAP IGS versions 7.20 through 7.53 permits unauthenticated remote command execution through externally-triggered IGS commands, enabling information disclosure and arbitrary file insertion or modification on affected systems.
Summary generated and translated by AI from the official description.
The SAP Internet Graphics Service (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to externally trigger IGS command executions which can lead to: disclosure of information and malicious file insertion or modification.
Affected products
SAP · SAP Internet Graphics Server (IGS)