CVE-1999-0695: Medium severity Sybase PowerDynamo vulnerability
The Sybase PowerDynamo personal web server allows attackers to read arbitrary files through a .. (dot dot) attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Sybase PowerDynamo personal web serverfrom your environment.Uninstall or remove the PowerDynamo personal web server component if it is not required.
- Configuration
Disable the PowerDynamo personal web server to prevent directory traversal attacks that allow arbitrary file reads.
Sybase PowerDynamo personal web server personal_web_server_enabled = false - Compensating control
Restrict network access to the PowerDynamo personal web server (for example, block or limit access via firewall/ACLs to trusted IPs or isolate the host) until a vendor fix or safe configuration is applied.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0695?
The severity of CVE-1999-0695 is considered high due to the potential for unauthorized file access.
How do I fix CVE-1999-0695?
To fix CVE-1999-0695, upgrade to a version of Sybase PowerDynamo that addresses this vulnerability or implement proper input validation.
What systems are affected by CVE-1999-0695?
CVE-1999-0695 affects Sybase PowerDynamo version 3.0.652.
What type of attack is associated with CVE-1999-0695?
CVE-1999-0695 is associated with a directory traversal attack, allowing attackers to read arbitrary files.
Is CVE-1999-0695 still a relevant vulnerability today?
CVE-1999-0695 remains relevant for environments still using Sybase PowerDynamo version 3.0.652, which is vulnerable to this exploit.