MEDIUM🇵🇱 Wersja polska

CVE-2019-0381

CVSS 5.5v3.1pub. 2019-10-08upd. 2024-11-21

A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of the paths specified by the user.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • Sap Dynamic Tier

    APP
    Sap
    1.02.0
  • Sap Iq

    APP
    Sap
    16.1
  • Sap Sql Anywhere

    APP
    Sap
    17.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-35299CRITICAL9.8PL ✓same product

Stack-based buffer overflow w SAP SQL Anywhere i SAP IQ

CVE-2023-33990HIGH7.8same product

SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by ...

CVE-2014-9264HIGH7.5same product

Stack-based buffer overflow in the .NET Data Provider in SAP SQL Anywhere allows remote attackers to execute a...

CVE-2022-41259MEDIUM6.5same product

SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a...

CVE-2022-27670MEDIUM6.5same product

SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a...