CVE-2023-33990
SAP SQL Anywhere - version 17.0, allows an attacker to prevent legitimate users from accessing the service by crashing the service. An attacker with low privileged account and access to the local system can write into the shared memory objects. This can be leveraged by an attacker to perform a Denial of Service. Further, an attacker might be able to modify sensitive data in shared memory objects.This issue only affects SAP SQL Anywhere on Windows. Other platforms are not impacted.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.04%
- CWE
- CWE-732, CWE-277
- Published
- 2023-07-11
- Last modified
- 2026-03-13
Affected products
- SAP_SE SAP SQL Anywhere
Weakness type
Related vulnerabilities
- CVE-2025-14988 — Incorrect Permission Assignment for Critical Resource vulnerability in iba Systems ibaPDA
- CVE-2026-21902 — Junos OS Evolved: PTX Series: A vulnerability allows a unauthenticated, network-based attacker to execute code as root
- CVE-2026-29188 — File Browser: TUS Delete Endpoint Bypasses Delete Permission Check
- CVE-2026-25770 — Wazuh has Privilege Escalation to Root via Cluster Protocol File Write
- CVE-2026-21765 — HCL BigFix Platform is affected by insecure permissions on private cryptographic keys
- CVE-2025-13941 — Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability
- CVE-2021-47742 — Epic Games Psyonix Rocket League <=1.95 Elevation of Privileges via Insecure Permissions
- CVE-2020-36938 — WinAVR Version 20100110 - Insecure Folder Permissions