7.5
CVSSv2

CVE-2019-14678

Published: 14/11/2019 Updated: 22/11/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 10 | Impact Score: 6 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

sas xml mapper 9.45

sas base_sas 9.4

Github Repositories

CVE-2019-14678: XML External Entity in SAS XML Mapper

CVE-2019-14678: XML External Entity in SAS XML Mapper SAS XML Mapper 945 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks This vulnerability also affects the XMLV2 LIBNAME engine wh