Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h3pp-99vq-4j5h

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The web administration interface in the server in Sybase M-Business Anywhere 6.7 before ESD# 3 and 7.0 before ESD# 7 does not require admin authentication for unspecified scripts, which allows remote authenticated users to list or delete user accounts, modify passwords, or read log files via HTTP requests, aka Bug IDs 678497 and 678499.

The web administration interface in the server in Sybase M-Business Anywhere 6.7 before ESD# 3 and 7.0 before ESD# 7 does not require admin authentication for unspecified scripts, which allows remote authenticated users to list or delete user accounts, modify passwords, or read log files via HTTP requests, aka Bug IDs 678497 and 678499.

EPSS

Процентиль: 57%
0.00355
Низкий

Связанные уязвимости

nvd
почти 14 лет назад

The web administration interface in the server in Sybase M-Business Anywhere 6.7 before ESD# 3 and 7.0 before ESD# 7 does not require admin authentication for unspecified scripts, which allows remote authenticated users to list or delete user accounts, modify passwords, or read log files via HTTP requests, aka Bug IDs 678497 and 678499.

EPSS

Процентиль: 57%
0.00355
Низкий