CVE-2014-5454: Medium severity SAS Visual Analytics vulnerability
Published Aug 25, 2014
·Updated
Unrestricted file upload vulnerability in the image upload module in SAS Visual Analytics 6.4M1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.
Affected Software
1 affected component
SAS Visual Analytics=6.4-m1
Event History
Aug 25, 2014
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5454?
CVE-2014-5454 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2014-5454?
To fix CVE-2014-5454, it is essential to apply the latest security patches from SAS for Visual Analytics 6.4M1.
3
Who is affected by CVE-2014-5454?
CVE-2014-5454 affects users of SAS Visual Analytics version 6.4M1 with the image upload module enabled.
4
What type of attack does CVE-2014-5454 facilitate?
CVE-2014-5454 facilitates arbitrary code execution attacks through unauthorized file uploads.
5
Can CVE-2014-5454 be exploited by unauthenticated users?
No, CVE-2014-5454 requires remote authenticated users to exploit the vulnerability.