Sql Anywhere

Vendor:

First CVE: Dec 11, 2014 · Active for 11 years

8
Total CVEs
More Total CVEs than 85% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Sql Anywhere over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 11, 2014
11 years ago
Most Recent CVE
Jul 11, 2023
1,109 days ago

CVE Severity & Scoring

Sql Anywhere8 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local2 (25.0%)
Network4 (50.0%)
Unknown2 (25.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (75.0%)
High0 (0.0%)
Unknown2 (25.0%)
User Interaction
None6 (75.0%)
Unknown2 (25.0%)
Required0 (0.0%)
Privileges Required
Low4 (50.0%)
High1 (12.5%)
None1 (12.5%)
Unknown2 (25.0%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SAP SQL Anywhere - version 17.0, and SAP IQ - version 16.1, allows an attacker to leverage logical errors in memory management to cause a memory corruption, such as Stack-based buf
Oct 11, 20229.830NONO
SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with low privileged account and acce
Jul 11, 20237.123NONO
SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashing the server with some queries
Nov 8, 20226.522NONO
A binary planting in SAP SQL Anywhere, before version 17.0, SAP IQ, before version 16.1, and SAP Dynamic Tier, before versions 1.0 and 2.0, can result in the inadvertent access of
Oct 8, 20195.520NONO
Stack-based buffer overflow in the .NET Data Provider in SAP SQL Anywhere allows remote attackers to execute arbitrary code via a crafted column alias.
Dec 11, 20147.520NONO
SAP SQL Anywhere - version 17.0, allows an authenticated attacker to prevent legitimate users from accessing a SQL Anywhere database server by crashing the server with some queries
Apr 12, 20226.517NONO
Buffer overflow in the MobiLink Synchronization Server component in SAP SQL Anywhere 17 and possibly earlier allows remote authenticated users to cause a denial of service (resourc
Apr 10, 20174.915NONO
SAP Sybase SQL Anywhere 11 and 16 allows remote attackers to cause a denial of service (crash) via a crafted request, aka SAP Security Note 2108161.
Apr 1, 20155.015NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Sql Anywhere

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
17.057.10.6%00
16.015.02.4%00
11.015.02.4%00