SAP ASE 16.0 SP02 PL03 and prior versions allow attackers who own SourceDB and TargetDB databases to elevate privileges to sa (system administrator) via dbcc import_sproc SQL injection.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Adaptive_server_enterprise | Sybase | * | 16.0 (including) |