CVE-2013-6245

high

Description

Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3. 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to execute arbitrary code via unspecified vectors.

References

https://service.sap.com/sap/support/notes/1893560

http://www.sybase.com/detail?id=1099371

http://www.securityfocus.com/bid/63310

http://www.layersevensecurity.com/docs/Layer%20Seven%20Security_Advisory_September%202013.pdf

http://scn.sap.com/docs/DOC-8218

http://osvdb.org/98899

Details

Source: Mitre, NVD

Published: 2013-10-24

Updated: 2013-11-25

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High