İçeriğe atla
Noroxi

sas kayıtları

sas üreticisine ait 21 yayımlanmış kayıt.

Tüm kayıtlar

21 kayıt
  • CVE-2019-14678
    41Planlayın

    SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways.

    KritikCVSS 10,0Kavram kanıtıEPSS %3

    sas · xml mapper14 Kas 2019

  • CVE-2002-2017
    41Planlayın

    sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious p

    KritikCVSS 10,0İstismar yokEPSS %2

    sas · base31 Ara 2002

  • CVE-2018-20732
    40Planlayın

    SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.

    KritikCVSS 9,8İstismar yokEPSS %4

    sas · web infrastructure platform16 Oca 2019

  • CVE-2014-2262
    38İzleyin

    Buffer overflow in the client application in Base SAS 9.2 TS2M3, SAS 9.3 TS1M1 and TS1M2, and SAS 9.4 TS1M0 allows user-assisted remote atta

    KritikCVSS 9,3İstismar yokEPSS %4

    sas · base sas28 Şub 2014

  • CVE-2007-6763
    35İzleyin

    SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources

    YüksekCVSS 8,8İstismar yokEPSS %1

    sas · sas drug development31 Tem 2019

  • CVE-2024-48733
    35İzleyin

    SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to execute arbitrary SQL

    YüksekCVSS 8,8İstismar yokEPSS %1

    30 Eki 2024

  • CVE-2024-48734
    35İzleyin

    Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote attacker to upload malic

    YüksekCVSS 8,8İstismar yokEPSS %1

    30 Eki 2024

  • CVE-2021-41569
    32İzleyin

    SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion.

    YüksekCVSS 7,5Kavram kanıtıEPSS %8

    sas · sas\/intrnet19 Kas 2021

  • CVE-2020-7667
    30İzleyin

    Arbitrary File Write via Archive Extraction (Zip Slip)

    YüksekCVSS 7,5İstismar yokEPSS %2

    sas · go rpm utils24 Haz 2020

  • CVE-2018-20733
    30İzleyin

    BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.

    YüksekCVSS 7,5İstismar yokEPSS %1

    sas · web infrastructure platform16 Oca 2019

  • CVE-2024-48735
    30İzleyin

    Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote attacker to access i

    YüksekCVSS 7,7İstismar yokEPSS %1

    30 Eki 2024

  • CVE-2002-0219
    28İzleyin

    Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to exe

    YüksekCVSS 7,2İstismar yokEPSS %0

    sas · sas base16 May 2002

  • CVE-2002-0218
    28İzleyin

    Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local

    YüksekCVSS 7,2İstismar yokEPSS %0

    sas · sas base16 May 2002

  • CVE-2002-2018
    28İzleyin

    sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentati

    YüksekCVSS 7,2İstismar yokEPSS %0

    sas · base31 Ara 2002

  • CVE-2014-5454
    25İzleyin

    Unrestricted file upload vulnerability in the image upload module in SAS Visual Analytics 6.4M1 allows remote authenticated users to execute

    OrtaCVSS 6,0İstismar yokEPSS %2

    sas · visual analytics25 Ağu 2014

  • CVE-2022-25256
    24İzleyin

    SAS Web Report Studio 4.4 allows XSS.

    OrtaCVSS 6,1Kavram kanıtıEPSS %1

    sas · web report studio18 Şub 2022

  • CVE-2015-9281
    24İzleyin

    Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page.

    OrtaCVSS 6,1İstismar yokEPSS %1

    sas · web infrastructure platform16 Oca 2019

  • CVE-2021-35475
    21İzleyin

    SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server.

    OrtaCVSS 5,4Kavram kanıtıEPSS %1

    sas · environment manager25 Haz 2021

  • CVE-2023-4932
    21İzleyin

    Reflected Cross-Site Scripting in SAS 9.4

    OrtaCVSS 5,4İstismar yokEPSS %1

    sas · integration technologies12 Ara 2023

  • CVE-2023-24724
    21İzleyin

    A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insuffic

    OrtaCVSS 5,4İstismar yokEPSS %1

    sas · web administration interface3 Nis 2023

  • CVE-2020-9350
    21İzleyin

    Graph Builder in SAS Visual Analytics 8.5 allows XSS via a graph template that is accessed directly.

    OrtaCVSS 5,4İstismar yokEPSS %1

    sas · visual analytics22 Şub 2020