MidnightBSD

Advisories for sas

CVE-2002-0218 HIGH

Format string vulnerability in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via format specifiers in a command line argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sas sas_integration_technologies 8.1
sas sas_base 8.0
sas sas_integration_technologies 8.0
sas sas_base 8.1
CVE-2002-0219 HIGH

Buffer overflow in (1) sastcpd in SAS/Base 8.0 and 8.1 or (2) objspawn in SAS/Integration Technologies 8.0 and 8.1 allows local users to execute arbitrary code via large command line argument.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sas sas_integration_technologies 8.1
sas sas_base 8.0
sas sas_integration_technologies 8.0
sas sas_base 8.1
CVE-2002-2017 HIGH

sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sas base 8.0
sas integration_technologies 8.0
CVE-2002-2018 HIGH

sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentation fault.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sas base 8.0
sas integration_technologies 8.0
CVE-2014-2262 HIGH

Buffer overflow in the client application in Base SAS 9.2 TS2M3, SAS 9.3 TS1M1 and TS1M2, and SAS 9.4 TS1M0 allows user-assisted remote attackers to execute arbitrary code via a crafted SAS program.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
sas base_sas 9.3
sas base_sas 9.2
sas base_sas 9.4
CVE-2014-5454 MEDIUM

Unrestricted file upload vulnerability in the image upload module in SAS Visual Analytics 6.4M1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
sas visual_analytics 6.4
CVE-2015-9281 MEDIUM

Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-79,

Products Affected

Vendor Product Version
sas web_infrastructure_platform 9.4
sas web_infrastructure_platform *
CVE-2018-20732 HIGH

SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-502,

Products Affected

Vendor Product Version
sas web_infrastructure_platform 9.4
sas web_infrastructure_platform *
CVE-2018-20733 MEDIUM

BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-611,

Products Affected

Vendor Product Version
sas web_infrastructure_platform 9.4
sas web_infrastructure_platform *