| CVE ID | CVE-2014-9264 | 
| CVSS SCORE | 8.5, AV:U/AC:M/Au:U/C:P/I:P/A:P | 
| AFFECTED VENDORS | 
                            
                            
                            SAP | 
                    
| AFFECTED PRODUCTS | 
                            
                            
                            SQL Anywhere | 
                    
| VULNERABILITY DETAILS | 
                             
 The specific flaw exists within the handling of the REPLICATE function. If an application allows untrusted input to be used as the length of a REPLICATE function in a query, even if the input is correctly filtered against SQL injection, an attacker could take advantage of an arithmetic truncation error to overflow a heap buffer and execute arbitrary code in the context of the application. 
  | 
                    
| ADDITIONAL DETAILS | 
                            
                            
                            
                             
  | 
                    
| DISCLOSURE TIMELINE | 
                            
  | 
                    
| CREDIT | John Leitch |