Sybase EAServer Multiple Security Vulnerabilities
BID:61358
Info
Sybase EAServer Multiple Security Vulnerabilities
| Bugtraq ID: | 61358 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 19 2013 12:00AM |
| Updated: | Jul 19 2013 12:00AM |
| Credit: | Gerhard Wagner and Bernhard Mueller of SEC Consult Vulnerability Lab |
| Vulnerable: |
Sybase EAServer 6.3.1 Sybase EAServer 6.3 Sybase EAServer 6.2 Sybase EAServer 6.0.2 Devel Edition Sybase EAServer 6.0 Sybase EAServer 5.5 Sybase EAServer 5.3 Sybase EAServer 5.2 Sybase EAServer 5.1 Sybase EAServer 5.0 |
| Not Vulnerable: | |
Discussion
Sybase EAServer Multiple Security Vulnerabilities
Sybase EAServer is prone to multiple security vulnerabilities including;
1. A directory-traversal vulnerability
2. An XML External Entity injection
3. A command execution vulnerability
Successful exploits will allow attackers to download and upload arbitrary files on the affected computer, obtain potentially sensitive information and execute arbitrary commands with the privileges of the user running the affected application.
Sybase EAServer 6.3.1 and prior are vulnerable.
Sybase EAServer is prone to multiple security vulnerabilities including;
1. A directory-traversal vulnerability
2. An XML External Entity injection
3. A command execution vulnerability
Successful exploits will allow attackers to download and upload arbitrary files on the affected computer, obtain potentially sensitive information and execute arbitrary commands with the privileges of the user running the affected application.
Sybase EAServer 6.3.1 and prior are vulnerable.
Exploit / POC
Sybase EAServer Multiple Security Vulnerabilities
Attackers can use standard tools to exploit this issue.
Proof-of-concept code is available. Please see the reference for more information.
Attackers can use standard tools to exploit this issue.
Proof-of-concept code is available. Please see the reference for more information.
Solution / Fix
Sybase EAServer Multiple Security Vulnerabilities
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this. Please contact the vendor for more information.