HIGH✓ PATCH🇵🇱 Wersja polska

CVE-2013-7245

CVSS 7.5v3.0pub. 2018-04-24upd. 2024-11-21

The Backup Server component in SAP Sybase ASE 15.7 before SP51 allows remote attackers to bypass access restrictions and perform database dumps by leveraging failure to validate credentials, aka SAP Security Note 1927859.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
  • Sybase Adaptive Server Enterprise

    APP
    Sybase
    15.7
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2016-7402CRITICAL9.8PL ✓same product

SAP ASE: privilege escalation do SA przez SQL injection w dbcc import_sproc

CVE-2017-5371HIGH7.5same product

Odata Server in SAP Adaptive Server Enterprise (ASE) 16 allows remote attackers to cause a denial of service (...

CVE-2014-6284HIGH7.5same product

SAP Adaptive Server Enterprise (ASE) before 15.7 SP132 and 16.0 before 16.0 SP01 allows remote attackers to by...

CVE-2015-1310HIGH7.5same product

SQL injection vulnerability in SAP Adaptive Server Enterprise (Sybase ASE) allows remote attackers to execute ...

CVE-2013-6859HIGH8.5same product

SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3. 15.5 before 15.5 ESD#5.3, and 15.7 before 1...