Sybase EAServer Web Service Remote Installation Vulnerability
28 Oct. 2011
Summary
Remote exploitation of a design vulnerability in Sybase EAServer could allow an attacker to install arbitrary web services. This condition can result in arbitrary code execution.
Vulnerable Systems:
* Versions of EAServer prior from 6.3 ESD#2, and 6.3.1
The vulnerability is due to a design error which allows a user to install or uninstall web services via a certain web application. This web application is installed by default on the EAServer HTTP Server and does not require authentication.
Vendor Status:
Sybase has released a fix which addresses this issue.
Patch Availability:
Information about downloadable vendor updates can be found by clicking on the URLs shown
http://downloads.sybase.com