SAS
SAS WEB Infrastructure Platform: vulnerabilities and CVEs
SAS WEB Infrastructure Platform has 3 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs3
Last 12 months0
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-20733 | High (7.5) | 1.1% | — | Jan 17, 2019 | BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE. |
| CVE-2018-20732 | Critical (9.8) | 4.0% | — | Jan 17, 2019 | SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant. |
| CVE-2015-9281 | Medium (6.1) | 0.65% | — | Jan 17, 2019 | Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page. |