Sap Se Sap Sql Anywhere vulnerabilities
4 known vulnerabilities affecting sap_se/sap_sql_anywhere.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2023-33990HIGHCVSS 7.1v17.02023-07-11
CVE-2023-33990 [HIGH] CWE-277 CVE-2023-33990: SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the s
SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with low privileged account and access to the local system can write into the shared memory objects. This can be leveraged by an attacker to perform a Denial of Service. Further, an attacker might be able to m
cvelistv5nvd
CVE-2022-41259MEDIUMCVSS 6.5v= 17.02022-11-08
CVE-2022-41259 [MEDIUM] CWE-89 CVE-2022-41259: SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from a
SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashing the server with some queries that use an ARRAY constructor.
cvelistv5nvd
CVE-2022-35299CRITICALCVSS 9.8v17.02022-10-11
CVE-2022-35299 [CRITICAL] CWE-121 CVE-2022-35299: SAP SQL Anywhere - version 17.0, and SAP IQ - version 16.1, allows an attacker to leverage logical e
SAP SQL Anywhere - version 17.0, and SAP IQ - version 16.1, allows an attacker to leverage logical errors in memory management to cause a memory corruption, such as Stack-based buffer overflow.
cvelistv5nvd
CVE-2019-0381MEDIUMCVSS 5.5fixed in 17.02019-10-08
CVE-2019-0381 [MEDIUM] CWE-552 CVE-2019-0381: A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dyn
A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of the paths specified by the user.
cvelistv5nvd