Vulnerability index

Browse CVEs

9 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Integration Technologies MEDIUM 5.4
CVE-2023-4932

SAS application is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in the `_program` parameter of the the `/SASStoredPr…

Mitigation only
Fix from $1,600 2023-12-12
Web Administration Interface MEDIUM 5.4
CVE-2023-24724

A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficient vali…

Mitigation only
Fix from $1,600 2023-04-03
Web Report Studio MEDIUM 6.1
CVE-2022-25256

SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_back…

Mitigation only
Fix from $1,600 2022-02-19
Environment Manager MEDIUM 5.4
CVE-2021-35475

SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when editing the Configuration Prop…

No fix yet
Fix from $1,600 2021-06-25
Visual Analytics MEDIUM 5.4
CVE-2020-9350

Graph Builder in SAS Visual Analytics 8.5 allows XSS via a graph template that is accessed directly.

Mitigation only
Fix from $1,600 2020-02-23
Xml Mapper CRITICAL 10.0
CVE-2019-14678

SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local …

Mitigation only
Fix from $2,300 2019-11-14
Visual Analytics MEDIUM 6.0
CVE-2014-5454

Unrestricted file upload vulnerability in the image upload module in SAS Visual Analytics 6.4M1 allows remote authenticated users to execute arbitrar…

No fix yet
Fix from $1,600 2014-08-25
Base Sas HIGH 9.3
CVE-2014-2262

Buffer overflow in the client application in Base SAS 9.2 TS2M3, SAS 9.3 TS1M1 and TS1M2, and SAS 9.4 TS1M0 allows user-assisted remote attackers to …

Mitigation only
Fix from $1,950 2014-03-01
Base HIGH 10.0
CVE-2002-2017

sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, w…

Mitigation only
Fix from $1,950 2002-12-31