CRITICAL🇵🇱 Wersja polska

CVE-2019-14678

CVSS 10.0v3.1pub. 2019-11-14upd. 2024-11-21

SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
  • HP Ux

    OS
    Hp
    all versions
  • IBM Aix

    OS
    Ibm
    all versions
  • IBM Z\/os

    OS
    Ibm
    all versions
  • Linux Kernel

    OS
    Linux
    all versions
  • Microsoft Windows

    OS
    Microsoft
    all versions
  • Microsoft Windows 10

    OS
    Microsoft
    all versions
  • Microsoft Windows 7

    OS
    Microsoft
    all versions
  • Microsoft Windows 8

    OS
    Microsoft
    all versions
  • Microsoft Windows 8.1

    OS
    Microsoft
    all versions
  • Microsoft Windows Server 2012

    OS
    Microsoft
    r2
  • Microsoft Windows Server 2016

    OS
    Microsoft
    all versions
  • Microsoft Windows Server 2019

    OS
    Microsoft
    all versions
  • Oracle Solaris

    OS
    Oracle
    all versions
  • Sas Base Sas

    APP
    Sas
    9.4
  • Sas Xml Mapper

    APP
    Sas
    9.45
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoSXXE
CWE
References

Related vulnerabilities

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2026-33824CRITICAL9.8⚠ KEVPL ✓same product

Double free w Windows IKE Extension umożliwia zdalne wykonanie kodu

CVE-2025-59287CRITICAL9.8⚠ KEVPL ✓same product

RCE w Windows Server Update Service (WSUS) — deserializacja danych

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP