Vulnerability Name: CVE-2011-0496 (CCN-64697) Assigned: 2011-01-11 Published: 2011-01-11 Updated: 2017-08-17 Summary: Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to install arbitrary web services and execute arbitrary code, related to a "design vulnerability." Per: http://www.sybase.com/detail?id=1091057
' Remote exploitation of a design vulnerability in Sybase EAServer could allow an attacker to install arbitrary web services, this condition can result in arbitrary code execution allowing attacker to gain control over the affected machine.
This also affects those products that include EAServer: Appeon, Replication Server Messaging Edition, and WorkSpace.' CVSS v3 Severity: 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): LowIntegrity (I): LowAvailibility (A): Low
CVSS v2 Severity: 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C )7.4 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P )5.5 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAthentication (Au): NoneImpact Metrics: Confidentiality (C): PartialIntegrity (I): PartialAvailibility (A): Partial
Vulnerability Type: CWE-noinfo Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2011-0496 Source: OSVDB Type: UNKNOWN70428 Source: CCN Type: SA42904Sybase EAServer Two Vulnerabilities Source: SECUNIA Type: Vendor Advisory42904 Source: CCN Type: OSVDB ID: 70428Sybase EAServer Unspecified Arbitrary Web Service Remote Installation Source: BID Type: UNKNOWN45809 Source: CCN Type: BID-45809Sybase EAServer Multiple Vulnerabilities Source: CCN Type: Sybase Web SitePossible security vulnerabilities in EAServer 6.3 and earlier. This also affects Appeon, Replication Server Messaging Edition, and WorkSpace Source: CONFIRM Type: Vendor Advisoryhttp://www.sybase.com/detail?id=1091057 Source: VUPEN Type: Vendor AdvisoryADV-2011-0125 Source: XF Type: UNKNOWNeaserver-web-services-code-exec(64697) Source: XF Type: UNKNOWNeaserver-web-services-code-exec(64697) Vulnerable Configuration: Configuration 1 :cpe:/a:sybase:appeon_for_powerbuilder:2.5:*:*:*:*:*:*:* OR cpe:/a:sybase:appeon_for_powerbuilder:2.6:*:*:*:*:*:*:* OR cpe:/a:sybase:appeon_for_powerbuilder:2.7:*:*:*:*:*:*:* OR cpe:/a:sybase:appeon_for_powerbuilder:2.8:*:*:*:*:*:*:* OR cpe:/a:sybase:appeon_for_powerbuilder:6.0:*:*:*:*:*:*:* OR cpe:/a:sybase:appeon_for_powerbuilder:6.1:*:*:*:*:*:*:* OR cpe:/a:sybase:appeon_for_powerbuilder:6.2:*:*:*:*:*:*:* OR cpe:/a:sybase:appeon_for_powerbuilder:6.5:*:*:*:*:*:*:* OR cpe:/a:sybase:easerver:5.0:*:*:*:*:*:*:* OR cpe:/a:sybase:easerver:5.0.1:*:*:*:*:*:*:* OR cpe:/a:sybase:easerver:5.1:*:*:*:*:*:*:* OR cpe:/a:sybase:easerver:5.2:*:*:*:*:*:*:* OR cpe:/a:sybase:easerver:5.2.1:*:*:*:*:*:*:* OR cpe:/a:sybase:easerver:5.3:*:*:*:*:*:*:* OR cpe:/a:sybase:easerver:5.5:*:*:*:*:*:*:* OR cpe:/a:sybase:easerver:6.0:*:*:*:*:*:*:* OR cpe:/a:sybase:easerver:6.0.2:*:*:*:*:*:*:* OR cpe:/a:sybase:easerver:6.1:*:*:*:*:*:*:* OR cpe:/a:sybase:easerver:6.2:*:*:*:*:*:*:* OR cpe:/a:sybase:easerver:6.3:*:*:*:*:*:*:* OR cpe:/a:sybase:easerver:6.3.1:*:*:*:*:*:*:* OR cpe:/a:sybase:replication_server:*:*:messaging:*:*:*:*:* OR cpe:/a:sybase:replication_server:15.2:*:messaging:*:*:*:*:* OR cpe:/a:sybase:sybase_workspace:*:*:*:*:*:*:*:* OR cpe:/a:sybase:sybase_workspace:1.0:*:*:*:*:*:*:* OR cpe:/a:sybase:sybase_workspace:1.5:*:*:*:*:*:*:* OR cpe:/a:sybase:sybase_workspace:1.6:*:*:*:*:*:*:* OR cpe:/a:sybase:sybase_workspace:1.7:*:*:*:*:*:*:* OR cpe:/a:sybase:sybase_workspace:2.0:*:*:*:*:*:*:* OR cpe:/a:sybase:sybase_workspace:2.0.1:*:*:*:*:*:*:* OR cpe:/a:sybase:sybase_workspace:2.0.2:*:*:*:*:*:*:* OR cpe:/a:sybase:sybase_workspace:2.1:*:*:*:*:*:*:* OR cpe:/a:sybase:sybase_workspace:2.1.2:*:*:*:*:*:*:* OR cpe:/a:sybase:sybase_workspace:2.5:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:sybase:easerver:6.3:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
sybase appeon for powerbuilder 2.5
sybase appeon for powerbuilder 2.6
sybase appeon for powerbuilder 2.7
sybase appeon for powerbuilder 2.8
sybase appeon for powerbuilder 6.0
sybase appeon for powerbuilder 6.1
sybase appeon for powerbuilder 6.2
sybase appeon for powerbuilder 6.5
sybase easerver 5.0
sybase easerver 5.0.1
sybase easerver 5.1
sybase easerver 5.2
sybase easerver 5.2.1
sybase easerver 5.3
sybase easerver 5.5
sybase easerver 6.0
sybase easerver 6.0.2
sybase easerver 6.1
sybase easerver 6.2
sybase easerver 6.3
sybase easerver 6.3.1
sybase replication server *
sybase replication server 15.2
sybase sybase workspace *
sybase sybase workspace 1.0
sybase sybase workspace 1.5
sybase sybase workspace 1.6
sybase sybase workspace 1.7
sybase sybase workspace 2.0
sybase sybase workspace 2.0.1
sybase sybase workspace 2.0.2
sybase sybase workspace 2.1
sybase sybase workspace 2.1.2
sybase sybase workspace 2.5
sybase easerver 6.3