CVE-2014-6283 - CVE House
Back to Database
Status published Medium CVE-2014-6283

SAP Adaptive Server Enterprise (ASE) 15.7 before SP122 or SP63,...

Vulnerability Description

SAP Adaptive Server Enterprise (ASE) 15.7 before SP122 or SP63, 15.5 before ESD#5.4, and 15.0.3 before ESD#4.4 does not properly restrict access, which allows remote authenticated database users to (1) overwrite the master encryption key or (2) trigger a buffer overflow via a crafted RPC message to the hacmpmsgxchg function, and possibly other vectors.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2014-6283

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

adaptive server enterprise
Vulnerable Versions:
15.0.3, 15.5, 15.7

Timeline

Official Publish: October 17th, 2014
Last Modified: August 6th, 2024
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.