SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashing the server with some queries that use an ARRAY constructor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HSap Sql Anywhere
APPSap17.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
SQLi
Related vulnerabilities
CVE-2022-35299CRITICAL9.8PL ✓same product
Stack-based buffer overflow w SAP SQL Anywhere i SAP IQ
CVE-2023-33990HIGH7.8same product
SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by ...
CVE-2014-9264HIGH7.5same product
Stack-based buffer overflow in the .NET Data Provider in SAP SQL Anywhere allows remote attackers to execute a...
CVE-2022-27670MEDIUM6.5same product
SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a...
CVE-2019-0381MEDIUM5.5same product
A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier,...