SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-10310

Buffer overflow in the MobiLink Synchronization Server component in SAP SQL Anywhere 17 and possibly earlier allows remote authenticated users to cause a denial of service (resource consumption and process crash) by sending a crafted packet several…

MEDIUM 4.9EPSS 2.02%

Does this matter?

Lower severity and a low EPSS score (2.02%). Track it; it rarely justifies an emergency change on its own.

Description

Buffer overflow in the MobiLink Synchronization Server component in SAP SQL Anywhere 17 and possibly earlier allows remote authenticated users to cause a denial of service (resource consumption and process crash) by sending a crafted packet several times, aka SAP Security Note 2308778.

CVSS 3.0
4.9 MEDIUMCVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
EPSS
2.02% probability · 80th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
sap/sql anywhere
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.