Записи sas
21 опубликованных записей вендора sas.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 9,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-502 Deserialization of Untrusted Data1
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
21 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
41В плане | CVE-2019-14678Proof of concept | SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways.sas · xml mapper · CWE-611 | Критическая10,0 | — | 3,0 % | 14 нояб. 2019 г. |
41В плане | CVE-2002-2017Эксплойта нет | sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious psas · base | Критическая10,0 | — | 2,5 % | 31 дек. 2002 г. |
40В плане | CVE-2018-20732Эксплойта нет | SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.sas · web infrastructure platform · CWE-502 | Критическая9,8 | — | 4,0 % | 16 янв. 2019 г. |
38Наблюдать | CVE-2014-2262Эксплойта нет | Buffer overflow in the client application in Base SAS 9.2 TS2M3, SAS 9.3 TS1M1 and TS1M2, and SAS 9.4 TS1M0 allows user-assisted remote attasas · base sas · CWE-119 | Критическая9,3 | — | 4,3 % | 28 февр. 2014 г. |
35Наблюдать | CVE-2007-6763Эксплойта нет | SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources sas · sas drug development · CWE-20 | Высокая8,8 | — | 1,3 % | 31 июл. 2019 г. |
35Наблюдать | CVE-2024-48733Эксплойта нет | SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to execute arbitrary SQLCWE-89 | Высокая8,8 | — | 0,7 % | 30 окт. 2024 г. |
35Наблюдать | CVE-2024-48734Эксплойта нет | Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote attacker to upload malicCWE-434 | Высокая8,8 | — | 0,6 % | 30 окт. 2024 г. |
32Наблюдать | CVE-2021-41569Proof of concept | SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion.sas · sas\/intrnet · CWE-829 | Высокая7,5 | — | 8,0 % | 19 нояб. 2021 г. |
30Наблюдать | CVE-2020-7667Эксплойта нет | Arbitrary File Write via Archive Extraction (Zip Slip)sas · go rpm utils · CWE-22 | Высокая7,5 | — | 1,6 % | 24 июн. 2020 г. |
30Наблюдать | CVE-2018-20733Эксплойта нет | BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.sas · web infrastructure platform · CWE-611 | Высокая7,5 | — | 1,1 % | 16 янв. 2019 г. |
30Наблюдать | CVE-2024-48735Эксплойта нет | Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote attacker to access iCWE-22 | Высокая7,7 | — | 1,0 % | 30 окт. 2024 г. |
28Наблюдать | CVE-2002-0219Эксплойта нет | Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to exesas · sas base | Высокая7,2 | — | 0,5 % | 16 мая 2002 г. |
28Наблюдать | CVE-2002-0218Эксплойта нет | Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local sas · sas base | Высокая7,2 | — | 0,4 % | 16 мая 2002 г. |
28Наблюдать | CVE-2002-2018Эксплойта нет | sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentatisas · base | Высокая7,2 | — | 0,3 % | 31 дек. 2002 г. |
25Наблюдать | CVE-2014-5454Эксплойта нет | Unrestricted file upload vulnerability in the image upload module in SAS Visual Analytics 6.4M1 allows remote authenticated users to executesas · visual analytics | Средняя6,0 | — | 2,4 % | 25 авг. 2014 г. |
24Наблюдать | CVE-2022-25256Proof of concept | SAS Web Report Studio 4.4 allows XSS.sas · web report studio · CWE-79 | Средняя6,1 | — | 1,2 % | 18 февр. 2022 г. |
24Наблюдать | CVE-2015-9281Эксплойта нет | Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page.sas · web infrastructure platform · CWE-79 | Средняя6,1 | — | 0,6 % | 16 янв. 2019 г. |
21Наблюдать | CVE-2021-35475Proof of concept | SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server.sas · environment manager · CWE-79 | Средняя5,4 | — | 0,9 % | 25 июн. 2021 г. |
21Наблюдать | CVE-2023-4932Эксплойта нет | Reflected Cross-Site Scripting in SAS 9.4sas · integration technologies · CWE-79 | Средняя5,4 | — | 0,6 % | 12 дек. 2023 г. |
21Наблюдать | CVE-2023-24724Эксплойта нет | A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficsas · web administration interface · CWE-79 | Средняя5,4 | — | 0,6 % | 3 апр. 2023 г. |
21Наблюдать | CVE-2020-9350Эксплойта нет | Graph Builder in SAS Visual Analytics 8.5 allows XSS via a graph template that is accessed directly.sas · visual analytics · CWE-79 | Средняя5,4 | — | 0,5 % | 22 февр. 2020 г. |
- CVE-2019-1467841В плане
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways.
КритическаяCVSS 10,0Proof of conceptEPSS 3 %sas · xml mapper14 нояб. 2019 г.
- CVE-2002-201741В плане
sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious p
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %sas · base31 дек. 2002 г.
- CVE-2018-2073240В плане
SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %sas · web infrastructure platform16 янв. 2019 г.
- CVE-2014-226238Наблюдать
Buffer overflow in the client application in Base SAS 9.2 TS2M3, SAS 9.3 TS1M1 and TS1M2, and SAS 9.4 TS1M0 allows user-assisted remote atta
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %sas · base sas28 февр. 2014 г.
- CVE-2007-676335Наблюдать
SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sas · sas drug development31 июл. 2019 г.
- CVE-2024-4873335Наблюдать
SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to execute arbitrary SQL
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %30 окт. 2024 г.
- CVE-2024-4873435Наблюдать
Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote attacker to upload malic
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %30 окт. 2024 г.
- CVE-2021-4156932Наблюдать
SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion.
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %sas · sas\/intrnet19 нояб. 2021 г.
- CVE-2020-766730Наблюдать
Arbitrary File Write via Archive Extraction (Zip Slip)
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %sas · go rpm utils24 июн. 2020 г.
- CVE-2018-2073330Наблюдать
BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %sas · web infrastructure platform16 янв. 2019 г.
- CVE-2024-4873530Наблюдать
Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote attacker to access i
ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %30 окт. 2024 г.
- CVE-2002-021928Наблюдать
Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to exe
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %sas · sas base16 мая 2002 г.
- CVE-2002-021828Наблюдать
Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %sas · sas base16 мая 2002 г.
- CVE-2002-201828Наблюдать
sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentati
ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %sas · base31 дек. 2002 г.
- CVE-2014-545425Наблюдать
Unrestricted file upload vulnerability in the image upload module in SAS Visual Analytics 6.4M1 allows remote authenticated users to execute
СредняяCVSS 6,0Эксплойта нетEPSS 2 %sas · visual analytics25 авг. 2014 г.
- CVE-2022-2525624Наблюдать
SAS Web Report Studio 4.4 allows XSS.
СредняяCVSS 6,1Proof of conceptEPSS 1 %sas · web report studio18 февр. 2022 г.
- CVE-2015-928124Наблюдать
Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %sas · web infrastructure platform16 янв. 2019 г.
- CVE-2021-3547521Наблюдать
SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server.
СредняяCVSS 5,4Proof of conceptEPSS 1 %sas · environment manager25 июн. 2021 г.
- CVE-2023-493221Наблюдать
Reflected Cross-Site Scripting in SAS 9.4
СредняяCVSS 5,4Эксплойта нетEPSS 1 %sas · integration technologies12 дек. 2023 г.
- CVE-2023-2472421Наблюдать
A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insuffic
СредняяCVSS 5,4Эксплойта нетEPSS 1 %sas · web administration interface3 апр. 2023 г.
- CVE-2020-935021Наблюдать
Graph Builder in SAS Visual Analytics 8.5 allows XSS via a graph template that is accessed directly.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %sas · visual analytics22 февр. 2020 г.