First published: Wed Feb 08 2012(Updated: )
The web administration interface in the server in Sybase M-Business Anywhere 6.7 before ESD# 3 and 7.0 before ESD# 7 does not require admin authentication for unspecified scripts, which allows remote authenticated users to list or delete user accounts, modify passwords, or read log files via HTTP requests, aka Bug IDs 678497 and 678499.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Sybase M-Business Anywhere | =6.7 | |
SAP Sybase M-Business Anywhere | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-5078 is considered to be of medium severity due to the potential unauthorized access it allows to administrative functions.
To fix CVE-2011-5078, you should update to Sybase M-Business Anywhere version 6.7 ESD# 3 or version 7.0 ESD# 7 or later.
CVE-2011-5078 could allow remote authenticated users to manipulate user accounts, passwords, and log files due to lack of admin authentication.
CVE-2011-5078 affects Sybase M-Business Anywhere versions 6.7 before ESD# 3 and 7.0 before ESD# 7.
There are no documented workarounds for CVE-2011-5078; updating to the appropriate version is recommended.