Lucene search

K

Sas Security Vulnerabilities

cve
cve

CVE-2023-50356

SSL connections to some LDAP servers are vulnerable to a man-in-the-middle attack due to improper certificate validation in AREAL Topkapi Vision (Server). This allows a remote unauthenticated attacker to gather sensitive information and prevent valid users from...

6.5CVSS

6.3AI Score

0.001EPSS

2024-01-31 11:15 AM
11
cve
cve

CVE-2023-50357

A cross site scripting vulnerability in the AREAL SAS Websrv1 ASP website allows a remote low-privileged attacker to gain escalated privileges of other non-admin...

5.4CVSS

5.5AI Score

0.001EPSS

2024-01-31 11:15 AM
10
cve
cve

CVE-2023-4932

SAS application is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in the _program parameter of the the /SASStoredProcess/do endpoint allows arbitrary JavaScript to be executed when specially crafted URL is opened by an authenticated user. The attack is possible from.....

6.3CVSS

5.4AI Score

0.001EPSS

2023-12-12 10:15 AM
9
cve
cve

CVE-2023-24724

A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficient validation and sanitization of data input into the user creation and editing form fields. The product name is SAS Web Administration interface...

5.4CVSS

5.2AI Score

0.001EPSS

2023-04-03 10:15 PM
16
cve
cve

CVE-2023-23720

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in NetReviews SAS Verified Reviews (Avis Vérifiés) plugin <= 2.3.13...

5.9CVSS

4.9AI Score

0.0005EPSS

2023-05-16 10:15 AM
10
cve
cve

CVE-2002-2017

sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by...

7.6AI Score

0.002EPSS

2022-10-03 04:23 PM
15
cve
cve

CVE-2002-2018

sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentation...

6.9AI Score

0.0004EPSS

2022-10-03 04:23 PM
22
cve
cve

CVE-2022-25256

SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_backurl_list. The first one affects the content of the button placed in the top left. The second affects the page to which the user is directed after...

6.1CVSS

5.9AI Score

0.001EPSS

2022-02-19 01:15 AM
65
cve
cve

CVE-2021-41569

SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows end-users of the application to access the sample.webcsf1.sas program, which contains user-controlled macro variables that are passed to the DS2CSF macro......

7.5CVSS

7.4AI Score

0.01EPSS

2021-11-19 06:15 PM
22
cve
cve

CVE-2021-35475

SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when editing the Configuration...

5.4CVSS

5.2AI Score

0.001EPSS

2021-06-25 11:15 AM
51
5
cve
cve

CVE-2020-7667

In package github.com/sassoftware/go-rpmutils/cpio before version 0.1.0, the CPIO extraction functionality doesn't sanitize the paths of the archived files for leading and non-leading ".." which leads in file extraction outside of the current directory. Note: the fixing commit was applied to all...

7.5CVSS

7.4AI Score

0.001EPSS

2020-06-24 12:15 PM
36
cve
cve

CVE-2020-9350

Graph Builder in SAS Visual Analytics 8.5 allows XSS via a graph template that is accessed...

5.4CVSS

5.2AI Score

0.001EPSS

2020-02-23 01:15 AM
85
cve
cve

CVE-2019-14678

SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects....

10CVSS

9.3AI Score

0.004EPSS

2019-11-14 09:15 PM
61
cve
cve

CVE-2007-6763

SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources by pressing a back or forward button in a web...

8.8CVSS

8.5AI Score

0.001EPSS

2019-07-31 06:15 PM
45
cve
cve

CVE-2019-5434

An attacker could send a specifically crafted payload to the XML-RPC invocation script and trigger the unserialize() call on the "what" parameter in the "openads.spc" RPC method. Such vulnerability could be used to perform various types of attacks, e.g. exploit serialize-related PHP...

9.8CVSS

9.6AI Score

0.281EPSS

2019-05-06 05:29 PM
65
cve
cve

CVE-2018-20733

BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows...

7.5CVSS

7.5AI Score

0.002EPSS

2019-01-17 01:29 AM
25
cve
cve

CVE-2018-20732

SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization...

9.8CVSS

9.7AI Score

0.01EPSS

2019-01-17 01:29 AM
28
cve
cve

CVE-2015-9281

Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout...

6.1CVSS

5.9AI Score

0.001EPSS

2019-01-17 01:29 AM
27
cve
cve

CVE-2014-5454

Unrestricted file upload vulnerability in the image upload module in SAS Visual Analytics 6.4M1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified...

7.5AI Score

0.003EPSS

2014-08-25 04:55 PM
15
cve
cve

CVE-2014-2262

Buffer overflow in the client application in Base SAS 9.2 TS2M3, SAS 9.3 TS1M1 and TS1M2, and SAS 9.4 TS1M0 allows user-assisted remote attackers to execute arbitrary code via a crafted SAS...

8AI Score

0.081EPSS

2014-03-01 12:55 AM
27
cve
cve

CVE-2002-0218

Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via format specifiers in a command line...

7.7AI Score

0.001EPSS

2002-05-16 04:00 AM
22
cve
cve

CVE-2002-0219

Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via large command line...

8AI Score

0.0004EPSS

2002-05-16 04:00 AM
20