A vulnerability has been identified in Sybase products, which could be exploited by remote attackers to gain knowledge of sensitive information. This issue is caused by an input validation error in EAServer when processing certain requests, which could allow remote attackers to disclose the contents of arbitrary files via a directory traversal.
Vulnerable Products
Vulnerable Software: Sybase EAServer version 6.3.1 and priorSybase Appeon versions 6.xSybase Replication Server Messaging Edition versions 15.xSybase WorkSpace versions 2.x