← Back to CVE List
Vulnerability Intelligence Report

CVE-2019-14678

SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.

No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
EPSS Probability:2.95%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
sas xml_mapper 9.45
sas base_sas 9.4
hp hp-ux all
ibm aix all
ibm z\/os all
linux linux_kernel all
microsoft windows all
microsoft windows_10 all
microsoft windows_7 all
microsoft windows_8 all
microsoft windows_8.1 all
microsoft windows_server_2012 r2
microsoft windows_server_2016 all
microsoft windows_server_2019 all
oracle solaris all

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
2.951%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2019-08-05T00:00:00
Published2019-11-14T20:59:44
Last Updated2024-08-05T00:19:41

LINK COPIED TO CLIPBOARD