SAP Sybase Event Stream Processor CVE-2014-3458 Multiple Remote Code Execution Vulnerabilities
BID:67587
Info
SAP Sybase Event Stream Processor CVE-2014-3458 Multiple Remote Code Execution Vulnerabilities
| Bugtraq ID: | 67587 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-3458 |
| Remote: | Yes |
| Local: | No |
| Published: | May 22 2014 12:00AM |
| Updated: | May 22 2014 12:00AM |
| Credit: | WanderingGlitch, HP Zero Day Initiative |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
SAP Sybase Event Stream Processor CVE-2014-3458 Multiple Remote Code Execution Vulnerabilities
SAP Sybase Event Stream Processor is prone to multiple remote code-execution vulnerabilities because it fails to properly sanitize the user-supplied input.
Successfully exploiting these issues may allow an attacker to execute arbitrary code in the context of the affected application.
SAP Sybase Event Stream Processor is prone to multiple remote code-execution vulnerabilities because it fails to properly sanitize the user-supplied input.
Successfully exploiting these issues may allow an attacker to execute arbitrary code in the context of the affected application.
Exploit / POC
SAP Sybase Event Stream Processor CVE-2014-3458 Multiple Remote Code Execution Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
SAP Sybase Event Stream Processor CVE-2014-3458 Multiple Remote Code Execution Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
SAP Sybase Event Stream Processor CVE-2014-3458 Multiple Remote Code Execution Vulnerabilities
References:
References:
- (0Day) SAP Sybase ESP esp_parse Connection.getErrors Remote Code Execution Vulne (zero day initiative)
- (0Day) SAP Sybase ESP esp_parse Connection.getType Remote Code Execution Vulnera (zero day initiative)
- (0Day) SAP Sybase ESP esp_parse ConnectionType.getName Remote Code Execution Vul (zero day initiative)
- (0Day) SAP Sybase ESP esp_parse ConnectionType.getParamNames Remote Code Executi (zero day initiative)
- (0Day) SAP Sybase ESP esp_parse ConnectionType.getXmlDescription Remote Code Exe (zero day initiative)
- SAP Sybase Event Stream Processor Homepage (SAP)