CVE-2011-0496
Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to install arbitrary web services and execute arbitrary code, related to a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.55%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to install arbitrary web services and execute arbitrary code, related to a "design vulnerability."
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 4.55% probability · 91th percentile
- CISA KEV
- Not listed
- Affected
- sybase/appeon for powerbuilder · sybase/easerver · sybase/replication server · sybase/sybase workspace
- Source
- cve@mitre.org
References
- http://osvdb.org/70428
- http://secunia.com/advisories/42904Vendor Advisory
- http://www.securityfocus.com/bid/45809
- http://www.sybase.com/detail?id=1091057Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0125Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64697
- http://osvdb.org/70428
- http://secunia.com/advisories/42904Vendor Advisory
- http://www.securityfocus.com/bid/45809
- http://www.sybase.com/detail?id=1091057Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0125Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/64697
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.