sas kayıtları
sas üreticisine ait 21 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %9,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-502 Deserialization of Untrusted Data1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
21 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2019-14678Kavram kanıtı | SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways.sas · xml mapper · CWE-611 | Kritik10,0 | — | %3,0 | 14 Kas 2019 |
41Planlayın | CVE-2002-2017İstismar yok | sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious psas · base | Kritik10,0 | — | %2,5 | 31 Ara 2002 |
40Planlayın | CVE-2018-20732İstismar yok | SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.sas · web infrastructure platform · CWE-502 | Kritik9,8 | — | %4,0 | 16 Oca 2019 |
38İzleyin | CVE-2014-2262İstismar yok | Buffer overflow in the client application in Base SAS 9.2 TS2M3, SAS 9.3 TS1M1 and TS1M2, and SAS 9.4 TS1M0 allows user-assisted remote attasas · base sas · CWE-119 | Kritik9,3 | — | %4,3 | 28 Şub 2014 |
35İzleyin | CVE-2007-6763İstismar yok | SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources sas · sas drug development · CWE-20 | Yüksek8,8 | — | %1,3 | 31 Tem 2019 |
35İzleyin | CVE-2024-48733İstismar yok | SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to execute arbitrary SQLCWE-89 | Yüksek8,8 | — | %0,7 | 30 Eki 2024 |
35İzleyin | CVE-2024-48734İstismar yok | Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote attacker to upload malicCWE-434 | Yüksek8,8 | — | %0,6 | 30 Eki 2024 |
32İzleyin | CVE-2021-41569Kavram kanıtı | SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion.sas · sas\/intrnet · CWE-829 | Yüksek7,5 | — | %8,0 | 19 Kas 2021 |
30İzleyin | CVE-2020-7667İstismar yok | Arbitrary File Write via Archive Extraction (Zip Slip)sas · go rpm utils · CWE-22 | Yüksek7,5 | — | %1,6 | 24 Haz 2020 |
30İzleyin | CVE-2018-20733İstismar yok | BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.sas · web infrastructure platform · CWE-611 | Yüksek7,5 | — | %1,1 | 16 Oca 2019 |
30İzleyin | CVE-2024-48735İstismar yok | Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote attacker to access iCWE-22 | Yüksek7,7 | — | %1,0 | 30 Eki 2024 |
28İzleyin | CVE-2002-0219İstismar yok | Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to exesas · sas base | Yüksek7,2 | — | %0,5 | 16 May 2002 |
28İzleyin | CVE-2002-0218İstismar yok | Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local sas · sas base | Yüksek7,2 | — | %0,4 | 16 May 2002 |
28İzleyin | CVE-2002-2018İstismar yok | sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentatisas · base | Yüksek7,2 | — | %0,3 | 31 Ara 2002 |
25İzleyin | CVE-2014-5454İstismar yok | Unrestricted file upload vulnerability in the image upload module in SAS Visual Analytics 6.4M1 allows remote authenticated users to executesas · visual analytics | Orta6,0 | — | %2,4 | 25 Ağu 2014 |
24İzleyin | CVE-2022-25256Kavram kanıtı | SAS Web Report Studio 4.4 allows XSS.sas · web report studio · CWE-79 | Orta6,1 | — | %1,2 | 18 Şub 2022 |
24İzleyin | CVE-2015-9281İstismar yok | Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page.sas · web infrastructure platform · CWE-79 | Orta6,1 | — | %0,6 | 16 Oca 2019 |
21İzleyin | CVE-2021-35475Kavram kanıtı | SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server.sas · environment manager · CWE-79 | Orta5,4 | — | %0,9 | 25 Haz 2021 |
21İzleyin | CVE-2023-4932İstismar yok | Reflected Cross-Site Scripting in SAS 9.4sas · integration technologies · CWE-79 | Orta5,4 | — | %0,6 | 12 Ara 2023 |
21İzleyin | CVE-2023-24724İstismar yok | A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficsas · web administration interface · CWE-79 | Orta5,4 | — | %0,6 | 3 Nis 2023 |
21İzleyin | CVE-2020-9350İstismar yok | Graph Builder in SAS Visual Analytics 8.5 allows XSS via a graph template that is accessed directly.sas · visual analytics · CWE-79 | Orta5,4 | — | %0,5 | 22 Şub 2020 |
- CVE-2019-1467841Planlayın
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways.
KritikCVSS 10,0Kavram kanıtıEPSS %3sas · xml mapper14 Kas 2019
- CVE-2002-201741Planlayın
sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious p
KritikCVSS 10,0İstismar yokEPSS %2sas · base31 Ara 2002
- CVE-2018-2073240Planlayın
SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.
KritikCVSS 9,8İstismar yokEPSS %4sas · web infrastructure platform16 Oca 2019
- CVE-2014-226238İzleyin
Buffer overflow in the client application in Base SAS 9.2 TS2M3, SAS 9.3 TS1M1 and TS1M2, and SAS 9.4 TS1M0 allows user-assisted remote atta
KritikCVSS 9,3İstismar yokEPSS %4sas · base sas28 Şub 2014
- CVE-2007-676335İzleyin
SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources
YüksekCVSS 8,8İstismar yokEPSS %1sas · sas drug development31 Tem 2019
- CVE-2024-4873335İzleyin
SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to execute arbitrary SQL
YüksekCVSS 8,8İstismar yokEPSS %130 Eki 2024
- CVE-2024-4873435İzleyin
Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote attacker to upload malic
YüksekCVSS 8,8İstismar yokEPSS %130 Eki 2024
- CVE-2021-4156932İzleyin
SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion.
YüksekCVSS 7,5Kavram kanıtıEPSS %8sas · sas\/intrnet19 Kas 2021
- CVE-2020-766730İzleyin
Arbitrary File Write via Archive Extraction (Zip Slip)
YüksekCVSS 7,5İstismar yokEPSS %2sas · go rpm utils24 Haz 2020
- CVE-2018-2073330İzleyin
BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.
YüksekCVSS 7,5İstismar yokEPSS %1sas · web infrastructure platform16 Oca 2019
- CVE-2024-4873530İzleyin
Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote attacker to access i
YüksekCVSS 7,7İstismar yokEPSS %130 Eki 2024
- CVE-2002-021928İzleyin
Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to exe
YüksekCVSS 7,2İstismar yokEPSS %0sas · sas base16 May 2002
- CVE-2002-021828İzleyin
Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local
YüksekCVSS 7,2İstismar yokEPSS %0sas · sas base16 May 2002
- CVE-2002-201828İzleyin
sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentati
YüksekCVSS 7,2İstismar yokEPSS %0sas · base31 Ara 2002
- CVE-2014-545425İzleyin
Unrestricted file upload vulnerability in the image upload module in SAS Visual Analytics 6.4M1 allows remote authenticated users to execute
OrtaCVSS 6,0İstismar yokEPSS %2sas · visual analytics25 Ağu 2014
- CVE-2022-2525624İzleyin
SAS Web Report Studio 4.4 allows XSS.
OrtaCVSS 6,1Kavram kanıtıEPSS %1sas · web report studio18 Şub 2022
- CVE-2015-928124İzleyin
Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page.
OrtaCVSS 6,1İstismar yokEPSS %1sas · web infrastructure platform16 Oca 2019
- CVE-2021-3547521İzleyin
SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server.
OrtaCVSS 5,4Kavram kanıtıEPSS %1sas · environment manager25 Haz 2021
- CVE-2023-493221İzleyin
Reflected Cross-Site Scripting in SAS 9.4
OrtaCVSS 5,4İstismar yokEPSS %1sas · integration technologies12 Ara 2023
- CVE-2023-2472421İzleyin
A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insuffic
OrtaCVSS 5,4İstismar yokEPSS %1sas · web administration interface3 Nis 2023
- CVE-2020-935021İzleyin
Graph Builder in SAS Visual Analytics 8.5 allows XSS via a graph template that is accessed directly.
OrtaCVSS 5,4İstismar yokEPSS %1sas · visual analytics22 Şub 2020