Vulnerability CVE-2006-1997


Published: 2006-04-25   Modified: 2012-02-12

Description:
Unspecified vulnerability in Sybase Pylon Anywhere groupware synchronization server before 7.0 allows local users to obtain sensitive information such as email and PIM data of another user via unknown attack vectors.

Type:

CWE-noinfo

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
2.1/10
2.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
Sybase -> Pylon anywhere 

 References:
http://www.sybase.com/detail?id=1040213
http://secunia.com/advisories/19784
http://xforce.iss.net/xforce/xfdb/25989
http://www.vupen.com/english/advisories/2006/1477
http://www.securityfocus.com/bid/17677

Copyright 2024, cxsecurity.com

 

Back to Top