Vulnerability Name: | CVE-2013-6859 (CCN-89640) | ||||||||
Assigned: | 2013-11-04 | ||||||||
Published: | 2013-11-04 | ||||||||
Updated: | 2013-11-25 | ||||||||
Summary: | SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3. 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 does not properly perform authorization, which allows remote authenticated users to gain privileges via unspecified vectors. | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 8.5 High (CVSS v2 Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C) 6.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-287 | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2013-6859 Source: CONFIRM Type: UNKNOWN http://scn.sap.com/docs/DOC-8218 Source: CCN Type: SA55537 Sybase Adaptive Server Enterprise Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 55537 Source: CCN Type: Sybase Web site Security Update for Adaptive Server Enterprise (ASE) Source: CONFIRM Type: Vendor Advisory http://www.sybase.com/detail?id=1099371 Source: XF Type: UNKNOWN sybase-ase-cve20136859-priv-esc(89640) Source: CONFIRM Type: UNKNOWN https://service.sap.com/sap/support/notes/1849356 Source: CCN Type: SAP Web site SAP Security Note 1849356 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |