Перейти к содержимому
Noroxi

Записи sas

21 опубликованных записей вендора sas.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
3
С записью об исправлении
9,5 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

21 записей
  • CVE-2019-14678
    41В плане

    SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways.

    КритическаяCVSS 10,0Proof of conceptEPSS 3 %

    sas · xml mapper14 нояб. 2019 г.

  • CVE-2002-2017
    41В плане

    sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious p

    КритическаяCVSS 10,0Эксплойта нетEPSS 2 %

    sas · base31 дек. 2002 г.

  • CVE-2018-20732
    40В плане

    SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.

    КритическаяCVSS 9,8Эксплойта нетEPSS 4 %

    sas · web infrastructure platform16 янв. 2019 г.

  • CVE-2014-2262
    38Наблюдать

    Buffer overflow in the client application in Base SAS 9.2 TS2M3, SAS 9.3 TS1M1 and TS1M2, and SAS 9.4 TS1M0 allows user-assisted remote atta

    КритическаяCVSS 9,3Эксплойта нетEPSS 4 %

    sas · base sas28 февр. 2014 г.

  • CVE-2007-6763
    35Наблюдать

    SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    sas · sas drug development31 июл. 2019 г.

  • CVE-2024-48733
    35Наблюдать

    SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to execute arbitrary SQL

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    30 окт. 2024 г.

  • CVE-2024-48734
    35Наблюдать

    Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote attacker to upload malic

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    30 окт. 2024 г.

  • CVE-2021-41569
    32Наблюдать

    SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion.

    ВысокаяCVSS 7,5Proof of conceptEPSS 8 %

    sas · sas\/intrnet19 нояб. 2021 г.

  • CVE-2020-7667
    30Наблюдать

    Arbitrary File Write via Archive Extraction (Zip Slip)

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    sas · go rpm utils24 июн. 2020 г.

  • CVE-2018-20733
    30Наблюдать

    BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    sas · web infrastructure platform16 янв. 2019 г.

  • CVE-2024-48735
    30Наблюдать

    Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote attacker to access i

    ВысокаяCVSS 7,7Эксплойта нетEPSS 1 %

    30 окт. 2024 г.

  • CVE-2002-0219
    28Наблюдать

    Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to exe

    ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %

    sas · sas base16 мая 2002 г.

  • CVE-2002-0218
    28Наблюдать

    Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local

    ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %

    sas · sas base16 мая 2002 г.

  • CVE-2002-2018
    28Наблюдать

    sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentati

    ВысокаяCVSS 7,2Эксплойта нетEPSS 0 %

    sas · base31 дек. 2002 г.

  • CVE-2014-5454
    25Наблюдать

    Unrestricted file upload vulnerability in the image upload module in SAS Visual Analytics 6.4M1 allows remote authenticated users to execute

    СредняяCVSS 6,0Эксплойта нетEPSS 2 %

    sas · visual analytics25 авг. 2014 г.

  • CVE-2022-25256
    24Наблюдать

    SAS Web Report Studio 4.4 allows XSS.

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    sas · web report studio18 февр. 2022 г.

  • CVE-2015-9281
    24Наблюдать

    Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page.

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    sas · web infrastructure platform16 янв. 2019 г.

  • CVE-2021-35475
    21Наблюдать

    SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server.

    СредняяCVSS 5,4Proof of conceptEPSS 1 %

    sas · environment manager25 июн. 2021 г.

  • CVE-2023-4932
    21Наблюдать

    Reflected Cross-Site Scripting in SAS 9.4

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    sas · integration technologies12 дек. 2023 г.

  • CVE-2023-24724
    21Наблюдать

    A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insuffic

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    sas · web administration interface3 апр. 2023 г.

  • CVE-2020-9350
    21Наблюдать

    Graph Builder in SAS Visual Analytics 8.5 allows XSS via a graph template that is accessed directly.

    СредняяCVSS 5,4Эксплойта нетEPSS 1 %

    sas · visual analytics22 февр. 2020 г.