cancel
Showing results for 
Search instead for 
Did you mean: 

Vulnerabilities

05-03-2016 11:18 PM
192 views 2 comments
0 Likes
SAP Managed Tags
Subscribe

I need to know about  the solutions associated with the CVE - 2013-6868 vulnerability , related to ASE and its different versions.

0 Likes

Accepted Solutions (0)

Answers (1)

Answers (1)

former_member188958
Active Contributor
0 Likes

The web page at NVD - Detail specifies the affected versions.  The solution would be to upgrade to a more recent rollup of whatever version of ASE you are running on.  

-bret

Former Member
0 Likes

Julio,

In other words, 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows local users to obtain sensitive information via unspecified vectors.

The specific vector in question, network vulnerability not requiring authentication...

So, apply the specific patches and / or upgrade to ASE 16.0 ASAP?

Cheers.

Jean-Pierre