CVE-2018-2420: SAP Internet Graphics Server
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, allows an attacker to upload any file (including script files) without proper file format validation.
Affected products
- SAP Internet Graphics Server: version 7.20 only; version 7.20ext only; version 7.45 only; version 7.49 only; version 7.53 only
Published 2018-05-09. Last modified 2026-06-17.