MEDIUM · 5.5

CVE-2019-0381

A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in dir...

Vulnerability Description

A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of the paths specified by the user.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
SapDynamic Tier1.0
SapSap Iq16.1
SapSql Anywhere17.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-0381?

CVE-2019-0381 is a vulnerability with a CVSS score of 5.5 (MEDIUM). A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in dir...

How severe is CVE-2019-0381?

CVE-2019-0381 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-0381?

Check the references section above for vendor advisories and patch information. Affected products include: Sap Dynamic Tier, Sap Sap Iq, Sap Sql Anywhere.