Skip to main content

Vendor archive

sybase CVEs

Beta · best-effort

37 CVEs tagged to vendor sybase11 Critical, 9 High, 15 Medium, 2 Low, 0 Unrated.

CVE-2013-7245

Published Apr 24, 2018

The Backup Server component in SAP Sybase ASE 15.7 before SP51 allows remote attackers to bypass access restrictions and perform database dumps by leveraging failure to validate c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-5371

Published Jan 23, 2017

Odata Server in SAP Adaptive Server Enterprise (ASE) 16 allows remote attackers to cause a denial of service (process crash) via a series of crafted requests, aka SAP Security Not…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-7402

Published Nov 3, 2016

SAP ASE 16.0 SP02 PL03 and prior versions allow attackers who own SourceDB and TargetDB databases to elevate privileges to sa (system administrator) via dbcc import_sproc SQL inje…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2014-6284

Published Jun 8, 2015

SAP Adaptive Server Enterprise (ASE) before 15.7 SP132 and 16.0 before 16.0 SP01 allows remote attackers to bypass the challenge and response mechanism and obtain access to the pr…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2015-1310

Published Jan 22, 2015

SQL injection vulnerability in SAP Adaptive Server Enterprise (Sybase ASE) allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Note 2113333.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2014-6283

Published Oct 17, 2014

SAP Adaptive Server Enterprise (ASE) 15.7 before SP122 or SP63, 15.5 before ESD#5.4, and 15.0.3 before ESD#4.4 does not properly restrict access, which allows remote authenticated…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6868

Published Nov 23, 2013

SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows local users to obtain sensitive…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6867

Published Nov 23, 2013

Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 before 15.7 SP50 or 15.7 SP100 allows remote attackers to cause a denial of service via unspecified v…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6866

Published Nov 23, 2013

SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to execute a…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-6865

Published Nov 23, 2013

SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to ex…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-6864

Published Nov 23, 2013

Directory traversal vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 al…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6863

Published Nov 23, 2013

SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to ga…

CVSS 9.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-6862

Published Nov 23, 2013

Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote att…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6861

Published Nov 23, 2013

Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows loc…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6860

Published Nov 23, 2013

Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote aut…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6859

Published Nov 23, 2013

SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3. 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 does not properly perform authorization, which…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2013-6245

Published Oct 24, 2013

Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3. 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote aut…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2013-6025

Published Oct 19, 2013

The XMLParse procedure in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 ESD 2 allows remote authenticated users to read arbitrary files via a SQL statement containing an XML do…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4340

Published Aug 15, 2012

Cross-site scripting (XSS) vulnerability in Sybase EAServer before 6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5078

Published Feb 8, 2012

The web administration interface in the server in Sybase M-Business Anywhere 6.7 before ESD# 3 and 7.0 before ESD# 7 does not require admin authentication for unspecified scripts,…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2475

Published Jun 9, 2011

Format string vulnerability in ECTrace.dll in the iMailGateway service in the Internet Mail Gateway in OneBridge Server and DMZ Proxy in Sybase OneBridge Mobile Data Suite 5.5 and…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-2474

Published Jun 9, 2011

Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary files via a /.\../\../\ sequence in a pat…

CVSS 5.0 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2008-0912

Published Feb 22, 2008

Multiple heap-based buffer overflows in mlsrv10.exe in Sybase MobiLink 10.0.1.3629 and earlier, as used by SQL Anywhere Developer Edition 10.0.1.3415 and probably other products,…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 37 CVEsPage 1 of 2