Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2023-4932 SAS application is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in the `_program` parameter of the the `/SASStoredPr… Integration Technologies Mitigation only Fix from $1,6002023-12-12 MEDIUM 5.4 CVE-2023-24724 A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficient vali… Web Administration Interface Mitigation only Fix from $1,6002023-04-03 MEDIUM 6.1 CVE-2022-25256 SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_back… Web Report Studio Mitigation only Fix from $1,6002022-02-19 HIGH 7.5 CVE-2021-41569EPSS 8% SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows end-us… Sas\/intrnet 9.4+ Fix from $1,9502021-11-19 MEDIUM 5.4 CVE-2021-35475 SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when editing the Configuration Prop… Environment Manager No fix yet Fix from $1,6002021-06-25 HIGH 7.5 CVE-2020-7667 In package github.com/sassoftware/go-rpmutils/cpio before version 0.1.0, the CPIO extraction functionality doesn't sanitize the paths of the archived… Go Rpm Utils 0.1.0+ Fix from $1,9502020-06-24 MEDIUM 5.4 CVE-2020-9350 Graph Builder in SAS Visual Analytics 8.5 allows XSS via a graph template that is accessed directly. Visual Analytics Mitigation only Fix from $1,6002020-02-23 CRITICAL 10.0 CVE-2019-14678 SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local … Xml Mapper Mitigation only Fix from $2,3002019-11-14 HIGH 8.8 CVE-2007-6763 SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources by pressi… Sas Drug Development 32drg02+ Fix from $1,9502019-07-31 CRITICAL 9.8 CVE-2018-20732 SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant. Web Infrastructure Platform 9.4+ Fix from $2,3002019-01-17 HIGH 7.5 CVE-2018-20733 BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE. Web Infrastructure Platform 9.4+ Fix from $1,9502019-01-17 MEDIUM 6.1 CVE-2015-9281 Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page. Web Infrastructure Platform 9.4+ Fix from $1,6002019-01-17 MEDIUM 6.0 CVE-2014-5454 Unrestricted file upload vulnerability in the image upload module in SAS Visual Analytics 6.4M1 allows remote authenticated users to execute arbitrar… Visual Analytics No fix yet Fix from $1,6002014-08-25 HIGH 9.3 CVE-2014-2262 Buffer overflow in the client application in Base SAS 9.2 TS2M3, SAS 9.3 TS1M1 and TS1M2, and SAS 9.4 TS1M0 allows user-assisted remote attackers to … Base Sas Mitigation only Fix from $1,9502014-03-01 HIGH 10.0 CVE-2002-2017 sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, w… Base Mitigation only Fix from $1,9502002-12-31 HIGH 7.2 CVE-2002-2018 sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentation fault. Base Patch available Fix from $1,9502002-12-31 HIGH 7.2 CVE-2002-0218 Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to … Sas Base Patch available Fix from $1,9502002-05-16 HIGH 7.2 CVE-2002-0219 Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbi… Sas Base Patch available Fix from $1,9502002-05-16