The SAP Internet Graphics Server (IGS), 7.20, 7.20EXT, 7.45, 7.49, 7.53, has insufficient request validation (for example, where the request is validated for authenticity and validity) and under certain conditions, will process invalid requests. Several areas of the SAP Internet Graphics Server (IGS) did not require sufficient input validation. Namely, the SAP Internet Graphics Server (IGS) HTTP and RFC listener, SAP Internet Graphics Server (IGS) portwatcher when registering a portwatcher to the multiplexer and the SAP Internet Graphics Server (IGS) multiplexer had insufficient input validation and thus allowing a malformed data packet to cause a crash.
Conclusion & alert: CVE-2018-2439 is rated Moderate Risk (49.8/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 1.56%). Core evidence: EPSS rose +1.01% over the last day, indicating growing attacker interest. Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.55% | 1.56% | +1.01% |
| 2 | 2025-06-10 | 0.58% | 0.55% | -0.03% |
| 3 | 2025-03-30 | — | 0.58% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.9 | 3.0 | MEDIUM |
|
2.2 | 3.6 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| sap | internet_graphics_server | 7.20 | cpe:2.3:a:sap:internet_graphics_server:7.20:*:*:*:*:*:*:* |
| sap | internet_graphics_server | 7.20ext | cpe:2.3:a:sap:internet_graphics_server:7.20ext:*:*:*:*:*:*:* |
| sap | internet_graphics_server | 7.45 | cpe:2.3:a:sap:internet_graphics_server:7.45:*:*:*:*:*:*:* |
| sap | internet_graphics_server | 7.49 | cpe:2.3:a:sap:internet_graphics_server:7.49:*:*:*:*:*:*:* |
| sap | internet_graphics_server | 7.53 | cpe:2.3:a:sap:internet_graphics_server:7.53:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.securityfocus.com/bid/104708 | Third Party Advisory VDB Entry |
| https://launchpad.support.sap.com/#/notes/2644147 | Permissions Required Vendor Advisory |
| https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000 | Vendor Advisory |