CVE-2022-41259
published 2022-11-08CVE-2022-41259: SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashing the…
PriorityP337medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.72%
49.4th percentile
SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashing the server with some queries that use an ARRAY constructor.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | sql_anywhere | — | — |
| sap_se | sap_sql_anywhere | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
request-tracker4 vulnerabilities
osv·2023-12-04·CVSS 7.5
CVE-2021-38562 request-tracker4 vulnerabilities
request-tracker4 vulnerabilities
It was discovered that Request Tracker incorrectly handled certain inputs. If
a user or an automated system were tricked into opening a specially crafted
input file, a remote attacker could possibly use this issue to obtain
sensitive information. (CVE-2021-38562, CVE-2022-25802, CVE-2023-41259,
CVE-2023-41260)
GHSA
GHSA-w86f-xj88-2xxm: SAP SQL Anywhere - version 17
ghsa_unreviewed·2022-11-09
CVE-2022-41259 [MEDIUM] GHSA-w86f-xj88-2xxm: SAP SQL Anywhere - version 17
SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashing the server with some queries that use an ARRAY constructor.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-08
Published