Vulnerability CVE-2013-6866


Published: 2013-11-23

Description:
SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to execute arbitrary code via unspecified vectors, aka CR736689.

Type:

CWE-94

(Improper Control of Generation of Code ('Code Injection'))

CVSS2 => (AV:N/AC:L/Au:S/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9/10
10/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Sybase -> Adaptive server enterprise 

 References:
https://service.sap.com/sap/support/notes/1893560
http://www.sybase.com/detail?id=1099371
http://secunia.com/advisories/55537
http://scn.sap.com/docs/DOC-8218

Copyright 2024, cxsecurity.com

 

Back to Top