sas
Enterprise Softwarecommercial
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting sas.
- CVE-2023-4932Reflected Cross-Site Scripting in SAS 9.46.3
- CVE-2023-24724A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficient validation and sanitization of data input into the u...5.4
- CVE-2022-25256SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_backurl_list. The first one affects the content of t...6.1
- CVE-2021-41569SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows end-users of the application to access the sample.webc...7.5
- CVE-2021-35475SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when editing the Configuration Properties.5.4
- CVE-2020-7667Arbitrary File Write via Archive Extraction (Zip Slip)7.5
- CVE-2020-9350Graph Builder in SAS Visual Analytics 8.5 allows XSS via a graph template that is accessed directly.5.4
- CVE-2019-14678SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Ser...10.0
- CVE-2007-6763SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources by pressing a back or forward button in a web browser.8.8
- CVE-2018-20733BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.7.5
- CVE-2018-20732SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.9.8
- CVE-2015-9281Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page.6.1
- CVE-2014-5454Unrestricted file upload vulnerability in the image upload module in SAS Visual Analytics 6.4M1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable ex...6.0
- CVE-2014-2262Buffer overflow in the client application in Base SAS 9.2 TS2M3, SAS 9.3 TS1M1 and TS1M2, and SAS 9.4 TS1M0 allows user-assisted remote attackers to execute arbitrary code via a crafted SAS program.9.3
- CVE-2002-2018sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentation fault.7.2