Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-14678


SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.


Published

2019-11-14T21:15:11.357

Last Modified

2024-11-21T04:27:07.170

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 10.0 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-611

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application sas xml_mapper 9.45 Yes
Application sas base_sas 9.4 Yes
Operating System hp hp-ux - No
Operating System ibm aix - No
Operating System ibm z\/os - No
Operating System linux linux_kernel - No
Operating System microsoft windows - No
Operating System microsoft windows_10 - No
Operating System microsoft windows_7 - No
Operating System microsoft windows_7 - No
Operating System microsoft windows_7 - No
Operating System microsoft windows_7 - No
Operating System microsoft windows_8 - No
Operating System microsoft windows_8 - No
Operating System microsoft windows_8.1 - No
Operating System microsoft windows_server_2012 - No
Operating System microsoft windows_server_2012 - No
Operating System microsoft windows_server_2012 r2 No
Operating System microsoft windows_server_2016 - No
Operating System microsoft windows_server_2019 - No
Operating System oracle solaris - No

References