SAS develops a broadly used analytics and data-management platform spanning integration technologies, web infrastructure, and base systems that sit deep in enterprise data pipelines and reporting workflows. Vulnerabilities affecting the vendor skew toward serious outcomes and show a moderate tendency toward public exploit availability, with recurring exposure in input-handling and deserialization weakness classes including cross-site scripting, XML external entity injection, and improper input validation that are characteristic of web-facing and data-processing software. Defenders should treat SAS platform updates as priority items given the vendor's prominence in critical business intelligence environments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sas over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-41569HIGH SAS/Intrnet 9.4 build 1520 and earlier allows Local File Inclusion. The samples library (included by default) in the appstart.sas file, allows end-users of the application to acces | Nov 19, 2021 | 7.5 | 42 | NO | YES |
CVE-2018-20732CRITICAL SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant. | Jan 17, 2019 | 9.8 | 31 | NO | NO |
CVE-2002-2017HIGH sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcp | Dec 31, 2002 | 10.0 | 31 | NO | NO |
CVE-2019-14678CRITICAL SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File | Nov 14, 2019 | 10.0 | 30 | NO | NO |
CVE-2007-6763HIGH SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources by pressing a back or forward button in | Jul 31, 2019 | 8.8 | 28 | NO | NO |
CVE-2020-7667HIGH In package github.com/sassoftware/go-rpmutils/cpio before version 0.1.0, the CPIO extraction functionality doesn't sanitize the paths of the archived files for leading and non-lead | Jun 24, 2020 | 7.5 | 25 | NO | NO |
CVE-2018-20733HIGH BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE. | Jan 17, 2019 | 7.5 | 24 | NO | NO |
CVE-2014-2262HIGH Buffer overflow in the client application in Base SAS 9.2 TS2M3, SAS 9.3 TS1M1 and TS1M2, and SAS 9.4 TS1M0 allows user-assisted remote attackers to execute arbitrary code via a cr | Mar 1, 2014 | 9.3 | 24 | NO | NO |
CVE-2002-2018HIGH sastcpd in SAS/Base 8.0 might allow local users to gain privileges by setting the netencralg environment variable, which causes a segmentation fault. | Dec 31, 2002 | 7.2 | 24 | NO | NO |
CVE-2022-25256MEDIUM SAS Web Report Studio 4.4 allows XSS. /SASWebReportStudio/logonAndRender.do has two parameters: saspfs_request_backlabel_list and saspfs_request_backurl_list. The first one affects | Feb 19, 2022 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sas.
Media articles that mention a CVE ID that affects a product developed by Sas — matched by CVE ID, not by vendor name.