CVE-2019-0381

A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of the paths specified by the user.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:sap:dynamic_tier:1.0:*:*:*:*:*:*:*
cpe:2.3:a:sap:dynamic_tier:2.0:*:*:*:*:*:*:*
cpe:2.3:a:sap:sap_iq:16.1:*:*:*:*:*:*:*
cpe:2.3:a:sap:sql_anywhere:17.0:*:*:*:*:*:*:*

History

21 Nov 2024, 04:16

Type Values Removed Values Added
References () https://launchpad.support.sap.com/#/notes/2792430 - Permissions Required () https://launchpad.support.sap.com/#/notes/2792430 - Permissions Required
References () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050 - Vendor Advisory () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=528123050 - Vendor Advisory

Information

Published : 2019-10-08 20:15

Updated : 2024-11-21 04:16


NVD link : CVE-2019-0381

Mitre link : CVE-2019-0381

CVE.ORG link : CVE-2019-0381


JSON object : View

Products Affected

sap

  • dynamic_tier
  • sql_anywhere
  • sap_iq
CWE
CWE-552

Files or Directories Accessible to External Parties