VYPR
Medium severity5.5NVD Advisory· Published Oct 8, 2019· Updated Jun 17, 2026

CVE-2019-0381

CVE-2019-0381

Description

A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of files located in directories outside of the paths specified by the user.

Affected products

10
  • SAP/Dynamic Tier2 versions
    cpe:2.3:a:sap:dynamic_tier:1.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sap:dynamic_tier:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:dynamic_tier:2.0:*:*:*:*:*:*:*
  • cpe:2.3:a:sap:sap_iq:16.1:*:*:*:*:*:*:*
  • SAP/SQL Anywhere2 versions
    cpe:2.3:a:sap:sql_anywhere:17.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sap:sql_anywhere:17.0:*:*:*:*:*:*:*
    • (no CPE)range: <17.0
  • Range: <1.0, <2.0
  • SAP/IQllm-fuzzy
    Range: <16.1
  • SAP SE/SAP Dynamic Tieringv5
    Range: < 1.0
  • SAP SE/SAP IQv5
    Range: < 16.1
  • SAP SE/SAP SQL Anywherev5
    Range: < 17.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.