|
|
|
![]() |
Vulnerability Note VU#259540SAP Internet Graphics Service buffer overflowOverviewSAP Internet Graphics Service contains a buffer overflow. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable system.I. DescriptionAccording to SAP,The Internet Graphics Service (IGS) constitutes the infrastructure to enable the application developer to display graphics in an Internet browser with a minimum of effort. This vulnerability may be triggered by sending a specially crafted HTTP request to a vulnerable IGS installation. II. ImpactA remote, unauthenticated attacker may be able to execute arbitrary code on a vulnerable system, possibly with elevated privileges.III. SolutionAccording to public reports, SAP has addressed this issue. More information is available SAP Note 968423.
References
This vulnerability was reported by Mariano Nuņez Di Croce. This document was written by Jeff Gennari.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||