10

CVE-2019-14678

Exploit
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sas ≫ Xml Mapper Version 9.45
Sas ≫ Base Sas Version 9.4 Update ts1m6
   Hp ≫ Hp-ux Version -
   Ibm ≫ Aix Version -
   Ibm ≫ Z/os Version -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version - HwPlatform x64
   Microsoft ≫ Windows 10 Version -
   Microsoft ≫ Windows 7 Version - Update - SwEdition enterprise
   Microsoft ≫ Windows 7 Version - Update - SwEdition home_premium
   Microsoft ≫ Windows 7 Version - Update - SwEdition professional
   Microsoft ≫ Windows 7 Version - Update - SwEdition ultimate
   Microsoft ≫ Windows 8 Version - SwEdition enterprise
   Microsoft ≫ Windows 8 Version - SwEdition pro
   Microsoft ≫ Windows 8.1 Version - SwEdition pro
   Microsoft ≫ Windows Server 2012 Version - SwEdition datacenter
   Microsoft ≫ Windows Server 2012 Version - SwEdition standard
   Microsoft ≫ Windows Server 2012 Version r2 SwEdition datacenter
   Microsoft ≫ Windows Server 2016 Version -
   Microsoft ≫ Windows Server 2019 Version -
   Oracle ≫ Solaris Version - HwPlatform x64
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.95% 0.854
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

http://support.sas.com/kb/64/719.html
Vendor Advisory
https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-14678-Unsafe%20XML%20Parsing-SAS%20XML%20Mapper
Third Party Advisory
Exploit