First published: Thu Jan 20 2011(Updated: )
Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to install arbitrary web services and execute arbitrary code, related to a "design vulnerability."
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Appeon for PowerBuilder | =2.5 | |
SAP Appeon for PowerBuilder | =2.6 | |
SAP Appeon for PowerBuilder | =2.7 | |
SAP Appeon for PowerBuilder | =2.8 | |
SAP Appeon for PowerBuilder | =6.0 | |
SAP Appeon for PowerBuilder | =6.1 | |
SAP Appeon for PowerBuilder | =6.2 | |
SAP Appeon for PowerBuilder | =6.5 | |
SAP Sybase EAServer | =5.0 | |
SAP Sybase EAServer | =5.0.1 | |
SAP Sybase EAServer | =5.1 | |
SAP Sybase EAServer | =5.2 | |
SAP Sybase EAServer | =5.2.1 | |
SAP Sybase EAServer | =5.3 | |
SAP Sybase EAServer | =5.5 | |
SAP Sybase EAServer | =6.0 | |
SAP Sybase EAServer | =6.0.2 | |
SAP Sybase EAServer | =6.1 | |
SAP Sybase EAServer | =6.2 | |
SAP Sybase EAServer | =6.3 | |
SAP Sybase EAServer | =6.3.1 | |
SAP Replication Server | ||
SAP Replication Server | =15.2 | |
Sybase Workspace | ||
Sybase Workspace | =1.0 | |
Sybase Workspace | =1.5 | |
Sybase Workspace | =1.6 | |
Sybase Workspace | =1.7 | |
Sybase Workspace | =2.0 | |
Sybase Workspace | =2.0.1 | |
Sybase Workspace | =2.0.2 | |
Sybase Workspace | =2.1 | |
Sybase Workspace | =2.1.2 | |
Sybase Workspace | =2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0496 is classified as a high severity vulnerability due to the potential for remote code execution.
To mitigate CVE-2011-0496, upgrade to Sybase EAServer version 6.3 ESD#2 or later and ensure that all applicable software components are also updated.
CVE-2011-0496 affects various versions of Sybase EAServer and SAP Appeon for PowerBuilder, as well as other related Sybase products.
CVE-2011-0496 allows remote attackers to install arbitrary web services and execute arbitrary code, which can lead to a full compromise of affected systems.
CVE-2011-0496 was reported in January 2011, highlighting vulnerabilities in Sybase EAServer prior to version 6.3 ESD#2.