Buffer Overflow in MobiLink Synchronization Server of SAP SQL Anywhere
CVE-2016-10310

4.9MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
10 April 2017

Summary

A buffer overflow vulnerability exists within the MobiLink Synchronization Server component in SAP SQL Anywhere. This flaw allows remote authenticated users to exploit the server by sending specially crafted packets multiple times. The exploitation may lead to a denial of service, resulting in resource consumption and potential process crashes, thereby impacting the availability of the server.

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.