6.5
CVE-2018-2385
- EPSS 0.91%
- Veröffentlicht 14.02.2018 12:29:01
- Zuletzt bearbeitet 21.11.2024 04:03:43
- Erkennungen
Under certain conditions a malicious user provoking a divide by zero crash can prevent legitimate users from accessing the SAP Internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53, and its services.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Internet Graphics Server Version 7.20
SAP ≫ Internet Graphics Server Version 7.20ext
SAP ≫ Internet Graphics Server Version 7.45
SAP ≫ Internet Graphics Server Version 7.49
SAP ≫ Internet Graphics Server Version 7.53
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.91% | 0.562 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.5 | 2.8 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
|
| NIST | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:N/I:N/A:P
|
CWE-369 Divide By Zero
The product divides a value by zero.
https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/
https://launchpad.support.sap.com/#/notes/2525222