Vulnerable Systems:
* Sybase ASE 15.0, 15.5 and 15.7
It is possible to execute Operating System commands using the Java call Runtime.getRuntime().exec().
Impact:
Any low privileged database user can execute Operating System commands on the Sybase server host with the privilege of the Sybase server process. The attack requires that Java is installed and enabled on Sybase ASE.