cve/2018/CVE-2018-2392.md

22 lines
974 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2018-2392](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-2392)
![](https://img.shields.io/static/v1?label=Product&message=SAP%20Internet%20Graphics%20Server&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D%207.20%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Missing%20XML%20Validation&color=brighgreen)
### Description
Under certain conditions SAP Internet Graphics Server (IGS) 7.20, 7.20EXT, 7.45, 7.49, 7.53, fails to validate XML External Entity appropriately causing the SAP Internet Graphics Server (IGS) to become unavailable.
### POC
#### Reference
- https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/
#### Github
- https://github.com/ARPSyndicate/cvemon
- https://github.com/ARPSyndicate/kenzer-templates
- https://github.com/Vladimir-Ivanov-Git/sap_igs_xxe
- https://github.com/developer3000S/PoC-in-GitHub
- https://github.com/hectorgie/PoC-in-GitHub