Vulnerable Systems:
* Sybase M-Business Anywhere server 6.7 (earlier than Windows Build255, SunOS Build257, Linux Build256)
* Sybase M-Business Anywhere server 7.0 (earlier than Windows Build669, SunOS Build670, Linux Build671)
Remote exploitation of a insecure permissions vulnerability in Sybase Inc.'s M-Business Anywhere could allow an attacker to execute privileged commands. This condition can result in account compromise. The Sybase M-Business platform provides a client for desktop and mobile phone device access to a backend M-Business Server. By default the M-Business Server allows a user to self-register and create their own account with limited permissions. A vulnerability exists in the web administration interface where by a regular user can log in and execute scripts meant for exclusive use by the 'admin' user, without requiring any further authentication.
Vendor Status:
Sybase has released a fix which addresses this issue.