// For flags

CVE-2014-6283

 

Severity Score

6.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

2
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

SAP Adaptive Server Enterprise (ASE) 15.7 before SP122 or SP63, 15.5 before ESD#5.4, and 15.0.3 before ESD#4.4 does not properly restrict access, which allows remote authenticated database users to (1) overwrite the master encryption key or (2) trigger a buffer overflow via a crafted RPC message to the hacmpmsgxchg function, and possibly other vectors.

SAP Adaptive Server Enterprise (ASE) 15.7 anterior a SP122 o SP63, 15.5 anterior a ESD#5.4 y 15.0.3 anterior a ESD#4.4 no restringen debidamente el acceso, lo que permite a usuarios autenticados de la base de datos (1) sobreescribir la clave maestra de cifrado o (2) provocar un desbordamiento de buffer a través de un mensaje RPC manipulado a la función hacmpmsgxchg y posiblemente otros vectores.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
Single
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-09-09 CVE Reserved
  • 2014-10-17 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-08-06 First Exploit
  • 2024-10-15 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Sybase
Search vendor "Sybase"
Adaptive Server Enterprise
Search vendor "Sybase" for product "Adaptive Server Enterprise"
15.0.3
Search vendor "Sybase" for product "Adaptive Server Enterprise" and version "15.0.3"
-
Affected
Sybase
Search vendor "Sybase"
Adaptive Server Enterprise
Search vendor "Sybase" for product "Adaptive Server Enterprise"
15.5
Search vendor "Sybase" for product "Adaptive Server Enterprise" and version "15.5"
-
Affected
Sybase
Search vendor "Sybase"
Adaptive Server Enterprise
Search vendor "Sybase" for product "Adaptive Server Enterprise"
15.7
Search vendor "Sybase" for product "Adaptive Server Enterprise" and version "15.7"
-
Affected