Easerver
Vendor:
First CVE: Dec 31, 2002 · Active for 23 years
8
Total CVEs
More Total CVEs than 85% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 15% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Easerver over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2002
23 years ago
Most Recent CVE
Aug 15, 2012
5,091 days ago
CVE Severity & Scoring
Easerver8 CVEs
13%
63%
25%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown8 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown8 (100.0%)
User Interaction
None0 (0.0%)
Unknown8 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (100.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2297MEDIUM Stack-based buffer overflow in TreeAction.do in Sybase EAServer 4.2.5 through 5.2 allows remote authenticated users to execute arbitrary code via a large javascript parameter. | Jul 19, 2005 | 4.6 | 69 | NO | YES |
CVE-2011-2474MEDIUM Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers to read arbitrary files via a /.\../\../\ sequence in a path | Jun 9, 2011 | 5.0 | 61 | NO | YES |
CVE-2011-0496HIGH Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to | Jan 20, 2011 | 10.0 | 29 | NO | NO |
CVE-2011-0497HIGH Directory traversal vulnerability in Sybase EAServer 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to | Jan 20, 2011 | 7.8 | 22 | NO | NO |
CVE-2012-4340MEDIUM Cross-site scripting (XSS) vulnerability in Sybase EAServer before 6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Aug 15, 2012 | 4.3 | 16 | NO | NO |
CVE-2002-1861MEDIUM Sybase Enterprise Application Server 4.0, when running on Windows, allows remote attackers to retrieve files in the WEB-INF directory, which contains Java class files and configura | Dec 31, 2002 | 5.0 | 15 | NO | NO |
CVE-2006-1829MEDIUM EAServer Manager in Sybase EAServer 5.2 and 5.3 allows remote authenticated users, possibly guests, to obtain password credentials of arbitrary users via unspecified vectors involv | Apr 19, 2006 | 4.0 | 14 | NO | NO |
Sybase EAServer 5.0 for HP-UX Itanium, 5.2 for IBM AIX, HP-UX PA-RISC, Linux x86, and Sun Solaris SPARC, and 5.3 for Sun Solaris SPARC does not properly protect passwords when they | May 22, 2006 | 3.5 | 13 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
25.0% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Easerver
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.3.1 | 3 | 7.6 | 23.5% | 0 | 1 |
| 6.3 | 2 | 8.9 | 3.4% | 0 | 0 |
| 6.2 | 2 | 8.9 | 3.4% | 0 | 0 |
| 6.1 | 2 | 8.9 | 3.4% | 0 | 0 |
| 6.0.2 | 2 | 8.9 | 3.4% | 0 | 0 |
| 6.0.1 | 1 | 4.3 | 0.9% | 0 | 0 |
| 6.0 | 3 | 7.4 | 2.6% | 0 | 0 |
| 5.5 | 3 | 7.4 | 2.6% | 0 | 0 |
| 5.3 | 5 | 5.9 | 1.8% | 0 | 0 |
| 5.2.1 | 3 | 7.4 | 2.6% | 0 | 0 |
| 5.2 | 6 | 5.7 | 13.9% | 0 | 1 |
| 5.1 | 4 | 6.7 | 20.5% | 0 | 1 |
| 5.0.1 | 3 | 7.4 | 2.6% | 0 | 0 |
| 5.0 | 5 | 6.0 | 16.4% | 0 | 1 |
| 4.2.5 | 2 | 4.5 | 37.6% | 0 | 1 |
| 4.0 | 2 | 4.7 | 1.5% | 0 | 0 |