CVE-2007-6763: Input Validation
Published Jul 31, 2019
·Updated
SAS Drug Development (SDD) before 32DRG02 mishandles logout actions, which allows a user (who was previously logged in) to access resources by pressing a back or forward button in a web browser.
Affected Software
1 affected component
SAS SAS Drug Development<32drg02
Event History
Jul 31, 2019
CVE Published
06:15 PM
CVE Published
via MITRE·09:08 PM
Data Sourced
via MITRE·09:08 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2007-6763.
2
What is the severity of CVE-2007-6763?
The severity of CVE-2007-6763 is high with a severity value of 8.8.
3
What software version is affected by CVE-2007-6763?
SAS Drug Development (SDD) version up to but not including 32DRG02 is affected by CVE-2007-6763.
4
How does CVE-2007-6763 manifest?
CVE-2007-6763 manifests as mishandled logout actions in SAS Drug Development (SDD), allowing a previously logged-in user to access resources by pressing a back or forward button in a web browser.
5
Where can I find more information about CVE-2007-6763?
You can find more information about CVE-2007-6763 in the SAS Drug Development (SDD) Release Notes for version 32DRG02.