Critical severity9.8NVD Advisory· Published Nov 3, 2016· Updated Jun 17, 2026
CVE-2016-7402
CVE-2016-7402
Description
SAP ASE 16.0 SP02 PL03 and prior versions allow attackers who own SourceDB and TargetDB databases to elevate privileges to sa (system administrator) via dbcc import_sproc SQL injection.
Affected products
2- cpe:2.3:a:sybase:adaptive_server_enterprise:*:*:*:*:*:*:*:*Range: <=16.0
Patches
Vulnerability mechanics
References
2- www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2016-017/nvdThird Party Advisory
- www.securityfocus.com/bid/92950nvd
News mentions
0No linked articles in our index yet.