SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HHP Ux
OSHpall versionsIBM Aix
OSIbmall versionsIBM Z\/os
OSIbmall versionsLinux Kernel
OSLinuxall versionsMicrosoft Windows
OSMicrosoftall versionsMicrosoft Windows 10
OSMicrosoftall versionsMicrosoft Windows 7
OSMicrosoftall versionsMicrosoft Windows 8
OSMicrosoftall versionsMicrosoft Windows 8.1
OSMicrosoftall versionsMicrosoft Windows Server 2012
OSMicrosoftr2Microsoft Windows Server 2016
OSMicrosoftall versionsMicrosoft Windows Server 2019
OSMicrosoftall versionsOracle Solaris
OSOracleall versionsSas Base Sas
APPSas9.4Sas Xml Mapper
APPSas9.45
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoSXXE
CWE
Related vulnerabilities
CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product
Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów
CVE-2026-33824CRITICAL9.8⚠ KEVPL ✓same product
Double free w Windows IKE Extension umożliwia zdalne wykonanie kodu
CVE-2025-59287CRITICAL9.8⚠ KEVPL ✓same product
RCE w Windows Server Update Service (WSUS) — deserializacja danych
CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product
Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty
CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product
Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP