Executive Summary

Informations
Name CVE-2014-6283 First vendor Publication 2014-10-17
Vendor Cve Last vendor Modification 2017-09-08

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:N/AC:L/Au:S/C:P/I:P/A:P)
Cvss Base Score 6.5 Attack Range Network
Cvss Impact Score 6.4 Attack Complexity Low
Cvss Expoit Score 8 Authentication Requires single instance
Calculate full CVSS 2.0 Vectors scores

Detail

SAP Adaptive Server Enterprise (ASE) 15.7 before SP122 or SP63, 15.5 before ESD#5.4, and 15.0.3 before ESD#4.4 does not properly restrict access, which allows remote authenticated database users to (1) overwrite the master encryption key or (2) trigger a buffer overflow via a crafted RPC message to the hacmpmsgxchg function, and possibly other vectors.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6283

CWE : Common Weakness Enumeration

% Id Name
100 % CWE-264 Permissions, Privileges, and Access Controls

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 3

Sources (Detail)

Source Url
CONFIRM http://scn.sap.com/docs/DOC-55451
https://service.sap.com/sap/support/notes/2044220
MISC http://blog.spiderlabs.com/2014/09/cve-2014-6283-sap-ase-missing-authorizatio...
https://www3.trustwave.com/spiderlabs/advisories/TWSL2014-013.txt
SECUNIA http://secunia.com/advisories/61238
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/99935

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
Date Informations
2021-05-04 12:33:35
  • Multiple Updates
2021-04-22 01:40:21
  • Multiple Updates
2020-05-23 00:42:01
  • Multiple Updates
2017-09-08 09:23:08
  • Multiple Updates
2016-09-06 21:20:18
  • Multiple Updates
2016-04-27 01:08:54
  • Multiple Updates
2015-01-22 17:23:13
  • Multiple Updates
2014-12-16 21:24:14
  • Multiple Updates
2014-10-24 17:23:18
  • Multiple Updates
2014-10-22 17:23:01
  • Multiple Updates
2014-10-18 05:28:33
  • First insertion