Back to Database
Status published
Critical
CVE-2016-7402
SAP ASE 16.0 SP02 PL03 and prior versions allow attackers...
Vulnerability Description
SAP ASE 16.0 SP02 PL03 and prior versions allow attackers who own SourceDB and TargetDB databases to elevate privileges to sa (system administrator) via dbcc import_sproc SQL injection.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-7402
Credits & Attribution
No credits recorded in the NVD database.
References
More from sybase
View All →CVE-2017-5371
Odata Server in SAP Adaptive Server Enterprise (ASE) 16 allows...
High
7.5
CVE-2015-1310
SQL injection vulnerability in SAP Adaptive Server Enterprise (Sybase ASE)...
High
7.5
CVE-2014-6284
SAP Adaptive Server Enterprise (ASE) before 15.7 SP132 and 16.0...
High
7.5
CVE-2014-6283
SAP Adaptive Server Enterprise (ASE) 15.7 before SP122 or SP63,...
Medium
6.5
CVE-2013-7245
The Backup Server component in SAP Sybase ASE 15.7 before...
High
7.5
Affected Vendor
sybase
View all reports →Affected Software
adaptive server enterprise
Vulnerable Versions:
0
Timeline
Official Publish:
November 3rd, 2016
Last Modified:
August 6th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.