CVE-2019-0381
Summary
| CVE | CVE-2019-0381 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-08 20:15:00 UTC |
| Updated | 2019-10-15 16:12:00 UTC |
| Description | A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of the paths specified by the user. |
Risk And Classification
Problem Types: CWE-552
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sap | Dynamic Tier | 1.0 | All | All | All |
| Application | Sap | Dynamic Tier | 2.0 | All | All | All |
| Application | Sap | Dynamic Tier | 1.0 | All | All | All |
| Application | Sap | Dynamic Tier | 2.0 | All | All | All |
| Application | Sap | Sap Iq | 16.1 | All | All | All |
| Application | Sap | Sap Iq | 16.1 | All | All | All |
| Application | Sap | Sql Anywhere | 17.0 | All | All | All |
| Application | Sap | Sql Anywhere | 17.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SAP Security Patch Day – October 2019 - Product Security Response at SAP - SCN Wiki | CONFIRM | wiki.scn.sap.com | Vendor Advisory |
| launchpad.support.sap.com | MISC | launchpad.support.sap.com | Permissions Required |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.