
CVE-2021-27626 – SAP NetWeaver ABAP IGS Memory Corruption
https://notcve.org/view.php?id=CVE-2021-27626
09 Jun 2021 — SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CMiniXMLParser::Parse() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified. SAP Internet Graphics Service, vers... • https://launchpad.support.sap.com/#/notes/3021050 • CWE-787: Out-of-bounds Write •

CVE-2021-27624 – SAP NetWeaver ABAP IGS Memory Corruption
https://notcve.org/view.php?id=CVE-2021-27624
09 Jun 2021 — SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CiXMLIStreamRawBuffer::readRaw () which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified. SAP Internet Graphics Ser... • https://launchpad.support.sap.com/#/notes/3021050 • CWE-787: Out-of-bounds Write •

CVE-2021-27622 – SAP NetWeaver ABAP IGS Memory Corruption
https://notcve.org/view.php?id=CVE-2021-27622
09 Jun 2021 — SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CDrawRaster::LoadImageFromMemory() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified. SAP Internet Graphics Se... • https://launchpad.support.sap.com/#/notes/3021050 • CWE-787: Out-of-bounds Write •

CVE-2021-27620 – SAP NetWeaver ABAP IGS Memory Corruption
https://notcve.org/view.php?id=CVE-2021-27620
09 Jun 2021 — SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method Ups::AddPart() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified. SAP Internet Graphics Service, versiones - 7... • https://launchpad.support.sap.com/#/notes/3021050 • CWE-787: Out-of-bounds Write •

CVE-2021-27623
https://notcve.org/view.php?id=CVE-2021-27623
09 Jun 2021 — SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CXmlUtility::CheckLength() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified. SAP Internet Graphics Service, v... • https://launchpad.support.sap.com/#/notes/3021050 • CWE-787: Out-of-bounds Write •

CVE-2021-27627 – SAP NetWeaver ABAP IGS Memory Corruption
https://notcve.org/view.php?id=CVE-2021-27627
09 Jun 2021 — SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method ChartInterpreter::DoIt() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified. SAP Internet Graphics Service, ver... • https://launchpad.support.sap.com/#/notes/3021050 • CWE-787: Out-of-bounds Write •

CVE-2021-27625 – SAP NetWeaver ABAP IGS Memory Corruption
https://notcve.org/view.php?id=CVE-2021-27625
09 Jun 2021 — SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method IgsData::freeMemory() which will trigger an internal memory corruption error in the system causing the system to crash and rendering it unavailable. In this attack, no data in the system can be viewed or modified. SAP Internet Graphics Service, versio... • https://launchpad.support.sap.com/#/notes/3021050 • CWE-787: Out-of-bounds Write •

CVE-2018-2442
https://notcve.org/view.php?id=CVE-2018-2442
14 Aug 2018 — In SAP BusinessObjects Business Intelligence, versions 4.0, 4.1 and 4.2, while viewing a Web Intelligence report from BI Launchpad, the user session details captured by an HTTP analysis tool could be reused in a HTML page while the user session is still valid. En SAP BusinessObjects Business Intelligence, en versiones 4.0, 4.1 y 4.2, mientras se visualiza un informe Web Intelligence del BI Launchpad, los detalles de la sesión de usuario capturados por una herramienta de análisis HTTP podrían reutilizarse en... • http://www.securityfocus.com/bid/105078 • CWE-352: Cross-Site Request Forgery (CSRF) •

CVE-2018-2438
https://notcve.org/view.php?id=CVE-2018-2438
10 Jul 2018 — The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has several denial-of-service vulnerabilities that allow an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49 y 7.53 tiene varias vulnerabilidades de denegación de servicio (DoS) que permiten que un atacante evite que usuarios legítimos accedan a un servicio, ya sea provocando su cierre inesperado o inundándolo. • http://www.securityfocus.com/bid/104707 •

CVE-2018-2439
https://notcve.org/view.php?id=CVE-2018-2439
10 Jul 2018 — The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request validation (for example, where the request is validated for authenticity and validity) and under certain conditions, will process invalid requests. Several areas of the SAP Internet Graphics Server (IGS) did not require sufficient input validation. Namely, the SAP Internet Graphics Server (IGS) HTTP and RFC listener, SAP Internet Graphics Server (IGS) portwatcher when registering a portwatcher to the multiplexe... • http://www.securityfocus.com/bid/104708 • CWE-20: Improper Input Validation •