ID

VAR-201506-0328


CVE

CVE-2015-4160


TITLE

SAP ASE Database Platform In SQL Injection vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2015-002927

DESCRIPTION

SQL injection vulnerability in SAP ASE Database Platform allows remote attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Notes: 2152278. SAP Sybase Adaptive Server Enterprise is a relational database management system. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database

Trust: 2.61

sources: NVD: CVE-2015-4160 // JVNDB: JVNDB-2015-002927 // CNVD: CNVD-2015-03410 // BID: 74798 // IVD: e3216a0c-1e7e-11e6-abef-000c29c66e3d

IOT TAXONOMY

category:['ICS']sub_category: -

Trust: 0.8

sources: IVD: e3216a0c-1e7e-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-03410

AFFECTED PRODUCTS

vendor:sapmodel:ase database platformscope:eqversion: -

Trust: 1.6

vendor:sapmodel:ase database platformscope: - version: -

Trust: 0.8

vendor:sapmodel:sybase adaptive server enterprisescope: - version: -

Trust: 0.6

vendor:ase database platformmodel: - scope:eqversion: -

Trust: 0.2

sources: IVD: e3216a0c-1e7e-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-03410 // JVNDB: JVNDB-2015-002927 // CNNVD: CNNVD-201506-038 // NVD: CVE-2015-4160

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2015-4160
value: HIGH

Trust: 1.0

NVD: CVE-2015-4160
value: HIGH

Trust: 0.8

CNVD: CNVD-2015-03410
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201506-038
value: HIGH

Trust: 0.6

IVD: e3216a0c-1e7e-11e6-abef-000c29c66e3d
value: HIGH

Trust: 0.2

nvd@nist.gov: CVE-2015-4160
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2015-03410
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

IVD: e3216a0c-1e7e-11e6-abef-000c29c66e3d
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.9 [IVD]

Trust: 0.2

sources: IVD: e3216a0c-1e7e-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-03410 // JVNDB: JVNDB-2015-002927 // CNNVD: CNNVD-201506-038 // NVD: CVE-2015-4160

PROBLEMTYPE DATA

problemtype:CWE-89

Trust: 1.8

sources: JVNDB: JVNDB-2015-002927 // NVD: CVE-2015-4160

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201506-038

TYPE

SQL injection

Trust: 0.8

sources: IVD: e3216a0c-1e7e-11e6-abef-000c29c66e3d // CNNVD: CNNVD-201506-038

CONFIGURATIONS

sources: JVNDB: JVNDB-2015-002927

PATCH

title:SAP Security Note 2152278url:http://scn.sap.com/docs/DOC-55451

Trust: 0.8

title:SAP Sybase Adaptive Server Enterprise SQL Injection Vulnerability Patchurl:https://www.cnvd.org.cn/patchInfo/show/59006

Trust: 0.6

sources: CNVD: CNVD-2015-03410 // JVNDB: JVNDB-2015-002927

EXTERNAL IDS

db:NVDid:CVE-2015-4160

Trust: 2.9

db:BIDid:74798

Trust: 1.9

db:CNVDid:CNVD-2015-03410

Trust: 0.8

db:CNNVDid:CNNVD-201506-038

Trust: 0.8

db:JVNDBid:JVNDB-2015-002927

Trust: 0.8

db:IVDid:E3216A0C-1E7E-11E6-ABEF-000C29C66E3D

Trust: 0.2

sources: IVD: e3216a0c-1e7e-11e6-abef-000c29c66e3d // CNVD: CNVD-2015-03410 // BID: 74798 // JVNDB: JVNDB-2015-002927 // CNNVD: CNNVD-201506-038 // NVD: CVE-2015-4160

REFERENCES

url:http://seclists.org/fulldisclosure/2015/may/96

Trust: 2.4

url:http://www.securityfocus.com/bid/74798

Trust: 1.6

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2015-4160

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2015-4160

Trust: 0.8

url:http://www.sap.com

Trust: 0.3

sources: CNVD: CNVD-2015-03410 // BID: 74798 // JVNDB: JVNDB-2015-002927 // CNNVD: CNNVD-201506-038 // NVD: CVE-2015-4160

CREDITS

ERPScan

Trust: 0.3

sources: BID: 74798

SOURCES

db:IVDid:e3216a0c-1e7e-11e6-abef-000c29c66e3d
db:CNVDid:CNVD-2015-03410
db:BIDid:74798
db:JVNDBid:JVNDB-2015-002927
db:CNNVDid:CNNVD-201506-038
db:NVDid:CVE-2015-4160

LAST UPDATE DATE

2025-04-13T23:26:45.183000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2015-03410date:2015-05-28T00:00:00
db:BIDid:74798date:2015-07-15T00:24:00
db:JVNDBid:JVNDB-2015-002927date:2015-06-04T00:00:00
db:CNNVDid:CNNVD-201506-038date:2015-06-03T00:00:00
db:NVDid:CVE-2015-4160date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:IVDid:e3216a0c-1e7e-11e6-abef-000c29c66e3ddate:2015-05-28T00:00:00
db:CNVDid:CNVD-2015-03410date:2015-05-28T00:00:00
db:BIDid:74798date:2015-05-21T00:00:00
db:JVNDBid:JVNDB-2015-002927date:2015-06-04T00:00:00
db:CNNVDid:CNNVD-201506-038date:2015-06-03T00:00:00
db:NVDid:CVE-2015-4160date:2015-06-02T14:59:20.237