VYPR
Medium severity5.5NVD Advisory· Published Oct 8, 2019· Updated Jun 17, 2026

CVE-2019-0381

CVE-2019-0381

Description

A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of the paths specified by the user.

Affected products

10
  • SAP/IQ2 versions
    cpe:2.3:a:sap:sap_iq:16.1:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sap:sap_iq:16.1:*:*:*:*:*:*:*
    • (no CPE)range: <16.1
  • SAP/Dynamic Tier3 versions
    cpe:2.3:a:sap:dynamic_tier:1.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:sap:dynamic_tier:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:dynamic_tier:2.0:*:*:*:*:*:*:*
    • (no CPE)range: <1.0, <2.0
  • SAP/SQL Anywhere2 versions
    cpe:2.3:a:sap:sql_anywhere:17.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sap:sql_anywhere:17.0:*:*:*:*:*:*:*
    • (no CPE)range: <17.0
  • SAP SE/SAP IQv5
    Range: < 16.1
  • SAP SE/SAP SQL Anywherev5
    Range: < 17.0
  • SAP SE/SAP Dynamic Tieringv5
    Range: < 1.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.