5.5

CVE-2019-0381

A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of the paths specified by the user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Dynamic Tier Version 1.0
SAP ≫ Dynamic Tier Version 2.0
SAP ≫ Sap Iq Version 16.1
SAP ≫ Sql Anywhere Version 17.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.31% 0.223
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-552 Files or Directories Accessible to External Parties

The product makes files or directories accessible to unauthorized actors, even though they should not be.

https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050
Vendor Advisory
https://launchpad.support.sap.com/#/notes/2792430
Permissions Required