V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2019-14678
CVE
CriticalConfirmedExploit available

SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples …

CVSS
10.0
Critical
EPSS
0.01
p74
Published
2019-01-01
Updated
2019-01-01
Description

SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.

Tags · CWE
Pre-auth
CWE-611
CAPEC-221
Affected products
Xml_mapper
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Timeline
2019-01-01
Published
2019-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.008 · p74
Known exploited (KEV)
No
Known exploits — Сканер-ВС
CVE-2019-14678
github-poc · https://github.com/mbadanoiu/CVE-2019-14678
Enterprise
Affected software
ProductVendorStatus
base_sas*Tracked
xml_mapper*Tracked
Source databases
CVE