7.5
CVE-2013-7245
- EPSS 0.25%
- Veröffentlicht 24.04.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 02:00:33
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The Backup Server component in SAP Sybase ASE 15.7 before SP51 allows remote attackers to bypass access restrictions and perform database dumps by leveraging failure to validate credentials, aka SAP Security Note 1927859.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sybase ≫ Adaptive Server Enterprise Version15.7
Sybase ≫ Adaptive Server Enterprise Version15.7 Updatesp50
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.486 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-285 Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.