← Back

CVE-2011-5078

nvd nist
Published: Feb 8, 2012Modified: Apr 29, 2026

JSON object

Loading...
6.5
Vector
AV:N/AC:L/Au:S/C:P/I:P/A:P
Exploitability: 8.0 / Impact: 6.4
Source: NVD

Description

The web administration interface in the server in Sybase M-Business Anywhere 6.7 before ESD# 3 and 7.0 before ESD# 7 does not require admin authentication for unspecified scripts, which allows remote authenticated users to list or delete user accounts, modify passwords, or read log files via HTTP requests, aka Bug IDs 678497 and 678499.

Affected (2)

1 product
M Business Anywhere
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Sybase
Version 6.7
Version 7.0

Related CWEs

Timeline

No history available yet.