Skip to main content

Vendor archive

sas CVEs

Beta · best-effort

18 CVEs tagged to vendor sas4 Critical, 7 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2023-4932

Published Dec 12, 2023

SAS application is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in the `_program` parameter of the the `/SASStoredProcess/do` endpoint allows arbi…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-24724

Published Apr 3, 2023

A stored cross site scripting (XSS) vulnerability was discovered in the user management module of the SAS 9.4 Admin Console, due to insufficient validation and sanitization of dat…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41569

Published Nov 19, 2021

SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows end-users of the application to acce…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-35475

Published Jun 25, 2021

SAS Environment Manager 2.5 allows XSS through the Name field when creating/editing a server. The XSS will prompt when editing the Configuration Properties.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-7667

Published Jun 24, 2020

In package github.com/sassoftware/go-rpmutils/cpio before version 0.1.0, the CPIO extraction functionality doesn't sanitize the paths of the archived files for leading and non-lea…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9350

Published Feb 23, 2020

Graph Builder in SAS Visual Analytics 8.5 allows XSS via a graph template that is accessed directly.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-14678

Published Nov 14, 2019

SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File…

CVSS 10.0 · Critical

CVE-2007-6763

Published Jul 31, 2019

SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources by pressing a back or forward button in…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2014-5454

Published Aug 25, 2014

Unrestricted file upload vulnerability in the image upload module in SAS Visual Analytics 6.4M1 allows remote authenticated users to execute arbitrary code by uploading a file wit…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-2262

Published Mar 1, 2014

Buffer overflow in the client application in Base SAS 9.2 TS2M3, SAS 9.3 TS1M1 and TS1M2, and SAS 9.4 TS1M0 allows user-assisted remote attackers to execute arbitrary code via a c…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-2017

Published Dec 31, 2002

sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastc…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2002-2018

Published Dec 31, 2002

sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentation fault.

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0218

Published May 16, 2002

Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via for…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2002-0219

Published May 16, 2002

Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via large command l…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort
Showing 1-18 of 18 CVEsPage 1 of 1