Sybase SQL Anywhere 9.0.0 contains a flaw that may lead to an unauthorized privilege escalation. There is a format string error in X__SPRINTF which may allow the attacker to execute code within the context of the database user.
Classification
Location:
Local / Remote,
Context Dependent
Attack Type:
Input Manipulation
Impact:
Loss of Integrity
Solution
Upgrade to version 9.0.0 build 1250 or higher, as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.