Binary Planting Vulnerability in SAP SQL Anywhere and Related Products by SAP
CVE-2019-0381

5.5MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
8 October 2019

Summary

A binary planting vulnerability exists in SAP SQL Anywhere, SAP IQ, and SAP Dynamic Tier, allowing unauthorized access to files located in directories outside user-specified paths. This could lead to potential data exposure or compromise, highlighting the importance of securing data access within these applications.

Affected Version(s)

SAP Dynamic Tiering < 1.0 < 1.0

SAP Dynamic Tiering < 2.0 < 2.0

SAP IQ < 16.1

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.