Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Sas

First CVE: May 16, 2002Active for: 24 yearsTotal CVEs: 18
38.4
VTI Score
Medium

SAS develops a broadly used analytics and data-management platform spanning integration technologies, web infrastructure, and base systems that sit deep in enterprise data pipelines and reporting workflows. Vulnerabilities affecting the vendor skew toward serious outcomes and show a moderate tendency toward public exploit availability, with recurring exposure in input-handling and deserialization weakness classes including cross-site scripting, XML external entity injection, and improper input validation that are characteristic of web-facing and data-processing software. Defenders should treat SAS platform updates as priority items given the vendor's prominence in critical business intelligence environments; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Sas over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 16, 2002
24 years ago
Most Recent CVE
Dec 12, 2023
955 days ago

Products(14 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-41569HIGH
SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows end-users of the application to acces
Nov 19, 20217.542NOYES
CVE-2018-20732CRITICAL
SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.
Jan 17, 20199.831NONO
CVE-2002-2017HIGH
sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcp
Dec 31, 200210.031NONO
CVE-2019-14678CRITICAL
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File
Nov 14, 201910.030NONO
CVE-2007-6763HIGH
SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources by pressing a back or forward button in
Jul 31, 20198.828NONO
CVE-2020-7667HIGH
In package github.com/sassoftware/go-rpmutils/cpio before version 0.1.0, the CPIO extraction functionality doesn't sanitize the paths of the archived files for leading and non-lead
Jun 24, 20207.525NONO
CVE-2018-20733HIGH
BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.
Jan 17, 20197.524NONO
CVE-2014-2262HIGH
Buffer overflow in the client application in Base SAS 9.2 TS2M3, SAS 9.3 TS1M1 and TS1M2, and SAS 9.4 TS1M0 allows user-assisted remote attackers to execute arbitrary code via a cr
Mar 1, 20149.324NONO
CVE-2002-2018HIGH
sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentation fault.
Dec 31, 20027.224NONO
CVE-2022-25256MEDIUM
SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_backurl_list. The first one affects
Feb 19, 20226.122NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
39%
50%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network12 (66.7%)
Unknown6 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (66.7%)
High0 (0.0%)
Unknown6 (33.3%)
User Interaction
None6 (33.3%)
Unknown6 (33.3%)
Required6 (33.3%)
Privileges Required
Low5 (27.8%)
High0 (0.0%)
None7 (38.9%)
Unknown6 (33.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
5.6% of CVEs· 96th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Sas.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Sas — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Sas's Products

View all 3 CNAs →

Top CWEs