ZeroHour

CVE-2016-7402

CVSS 3.0
9.8 critical
EPSS
1%p63
Published
()
Modified
Description

SAP ASE 16.0 SP02 PL03 and prior versions allow attackers who own SourceDB and TargetDB databases to elevate privileges to sa (system administrator) via dbcc import_sproc SQL injection.

Vendors
sybase
Products
adaptive server enterprise
Weakness
CWE-264
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.