Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-65vm-7c4g-83vm

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 10

Описание

SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.

SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.

EPSS

Процентиль: 74%
0.00798
Низкий

10 Critical

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 10
nvd
около 6 лет назад

SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.

EPSS

Процентиль: 74%
0.00798
Низкий

10 Critical

CVSS3

Дефекты

CWE-611