First published: Tue Apr 12 2022(Updated: )
SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashing the server with some queries that use indirect identifiers.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP SQL Anywhere | =17.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SAP SQL Anywhere vulnerability is CVE-2022-27670.
The severity of CVE-2022-27670 is medium (6.5).
An attacker can exploit CVE-2022-27670 by crashing the SAP SQL Anywhere database server with certain queries that use indirect identifiers.
Version 17.0 of SAP SQL Anywhere is affected by CVE-2022-27670.
Yes, you can find references for CVE-2022-27670 at the following links: [Reference 1](https://launchpad.support.sap.com/#/notes/3148094) and [Reference 2](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).