Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Integration Technologies MEDIUM 5.4
CVE-2023-4932

SAS application is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in the `_program` parameter of the the `/SASStoredPr…

Mitigation only
Fix from $1,600 2023-12-12
Web Administration Interface MEDIUM 5.4
CVE-2023-24724

A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficient vali…

Mitigation only
Fix from $1,600 2023-04-03
Web Report Studio MEDIUM 6.1
CVE-2022-25256

SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_back…

Mitigation only
Fix from $1,600 2022-02-19
Sas\/intrnet HIGH 7.5
CVE-2021-41569EPSS 8%

SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows end-us…

Fix: 9.4+
Fix from $1,950 2021-11-19
Environment Manager MEDIUM 5.4
CVE-2021-35475

SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when editing the Configuration Prop…

No fix yet
Fix from $1,600 2021-06-25
Go Rpm Utils HIGH 7.5
CVE-2020-7667

In package github.com/sassoftware/go-rpmutils/cpio before version 0.1.0, the CPIO extraction functionality doesn't sanitize the paths of the archived…

Fix: 0.1.0+
Fix from $1,950 2020-06-24
Visual Analytics MEDIUM 5.4
CVE-2020-9350

Graph Builder in SAS Visual Analytics 8.5 allows XSS via a graph template that is accessed directly.

Mitigation only
Fix from $1,600 2020-02-23
Xml Mapper CRITICAL 10.0
CVE-2019-14678

SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local …

Mitigation only
Fix from $2,300 2019-11-14
Sas Drug Development HIGH 8.8
CVE-2007-6763

SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources by pressi…

Fix: 32drg02+
Fix from $1,950 2019-07-31
Web Infrastructure Platform CRITICAL 9.8
CVE-2018-20732

SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.

Fix: 9.4+
Fix from $2,300 2019-01-17
Web Infrastructure Platform HIGH 7.5
CVE-2018-20733

BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.

Fix: 9.4+
Fix from $1,950 2019-01-17
Web Infrastructure Platform MEDIUM 6.1
CVE-2015-9281

Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page.

Fix: 9.4+
Fix from $1,600 2019-01-17
Visual Analytics MEDIUM 6.0
CVE-2014-5454

Unrestricted file upload vulnerability in the image upload module in SAS Visual Analytics 6.4M1 allows remote authenticated users to execute arbitrar…

No fix yet
Fix from $1,600 2014-08-25
Base Sas HIGH 9.3
CVE-2014-2262

Buffer overflow in the client application in Base SAS 9.2 TS2M3, SAS 9.3 TS1M1 and TS1M2, and SAS 9.4 TS1M0 allows user-assisted remote attackers to …

Mitigation only
Fix from $1,950 2014-03-01
Base HIGH 10.0
CVE-2002-2017

sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, w…

Mitigation only
Fix from $1,950 2002-12-31
Base HIGH 7.2
CVE-2002-2018

sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentation fault.

Patch available
Fix from $1,950 2002-12-31
Sas Base HIGH 7.2
CVE-2002-0218

Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to …

Patch available
Fix from $1,950 2002-05-16
Sas Base HIGH 7.2
CVE-2002-0219

Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbi…

Patch available
Fix from $1,950 2002-05-16