CVE-2011-2475
Last modified
CVE-2011-2475 is a vulnerability of currently unknown severity. Format string vulnerability in ECTrace.dll in the iMailGateway service in the Internet Mail Gateway in OneBridge Server and DMZ Proxy in Sybase OneBridge Mobile Data Suite 5.5 and 5.6 allows remote attackers to execute arbitrary code via format string specifiers in unspecified string fields, related to authentication logging.. EPSS estimates a 3.68% chance of exploitation in the next 30 days.
Description
Format string vulnerability in ECTrace.dll in the iMailGateway service in the Internet Mail Gateway in OneBridge Server and DMZ Proxy in Sybase OneBridge Mobile Data Suite 5.5 and 5.6 allows remote attackers to execute arbitrary code via format string specifiers in unspecified string fields, related to authentication logging.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sybase | Onebridge Mobile Data Suite | 5.5 |
| Sybase | Onebridge Mobile Data Suite | 5.6 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2011-2475?
How severe is CVE-2011-2475?
How do I fix CVE-2011-2475?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2011
- CVE-2011-2468Directory traversal vulnerability in the web interface in An…
- CVE-2011-2470Cross-site scripting (XSS) vulnerability in chat/base/admin/…
- CVE-2011-2471utils/opcontrol in OProfile 0.9.6 and earlier might allow lo…
- CVE-2011-2472Directory traversal vulnerability in utils/opcontrol in OPro…
- CVE-2011-2473The do_dump_data function in utils/opcontrol in OProfile 0.9…
- CVE-2011-2474Directory traversal vulnerability in the HTTP Server in Syba…
- CVE-2011-2476Cross-site scripting (XSS) vulnerability in Coppermine Photo…
- CVE-2011-2477Multiple cross-site scripting (XSS) vulnerabilities in confi…
- CVE-2011-2478Google SketchUp before 8 does not properly handle edge geome…
- CVE-2011-2479The Linux kernel before 2.6.39 does not properly create tran…5.5
- CVE-2011-2480Information Disclosure vulnerability in the 802.11 stack, as…7.5
- CVE-2011-2481Apache Tomcat 7.0.x before 7.0.17 permits web applications t…
Are you affected by CVE-2011-2475?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
