CVE-2014-6283
SAP Adaptive Server Enterprise (ASE) 15.7 before SP122 or SP63, 15.5 before ESD#5.4, and 15.0.3 before ESD#4.4 does not properly restrict access, which allows remote authenticated database users to (1) overwrite the master encryption key or (2) trigger…
Does this matter?
Lower severity and a low EPSS score (1.15%). Track it; it rarely justifies an emergency change on its own.
Description
SAP Adaptive Server Enterprise (ASE) 15.7 before SP122 or SP63, 15.5 before ESD#5.4, and 15.0.3 before ESD#4.4 does not properly restrict access, which allows remote authenticated database users to (1) overwrite the master encryption key or (2) trigger a buffer overflow via a crafted RPC message to the hacmpmsgxchg function, and possibly other vectors.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.15% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- sybase/adaptive server enterprise
- Source
- cve@mitre.org
References
- http://blog.spiderlabs.com/2014/09/cve-2014-6283-sap-ase-missing-authorization-checks-and-arbitrary-code-execution.htmlExploit, Third Party Advisory
- http://scn.sap.com/docs/DOC-55451Vendor Advisory
- http://secunia.com/advisories/61238
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99935
- https://service.sap.com/sap/support/notes/2044220Permissions Required, Vendor Advisory
- https://www3.trustwave.com/spiderlabs/advisories/TWSL2014-013.txtExploit, Third Party Advisory
- http://blog.spiderlabs.com/2014/09/cve-2014-6283-sap-ase-missing-authorization-checks-and-arbitrary-code-execution.htmlExploit, Third Party Advisory
- http://scn.sap.com/docs/DOC-55451Vendor Advisory
- http://secunia.com/advisories/61238
- https://exchange.xforce.ibmcloud.com/vulnerabilities/99935
- https://service.sap.com/sap/support/notes/2044220Permissions Required, Vendor Advisory
- https://www3.trustwave.com/spiderlabs/advisories/TWSL2014-013.txtExploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.