CVE-2018-20732: Critical severity sas web infrastructure platform vulnerability
Published Jan 17, 2019
·Updated
SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.
Affected Software
12 affected components
SAS Web Infrastructure Platform<9.4
SAS Web Infrastructure Platform=9.4
SAS Web Infrastructure Platform=9.4-maintenance_release_1
SAS Web Infrastructure Platform=9.4-maintenance_release_2
SAS Web Infrastructure Platform=9.4-maintenance_release_3
SAS Web Infrastructure Platform=9.4-maintenance_release_4
SAS Web Infrastructure Platform=9.4-maintenance_release_5
HPE Hp-ux Ipfilter
IBM AIX
Linux Linux kernel
Microsoft Windows
Oracle Solaris
Event History
Jan 17, 2019
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2018-20732.
2
What is the severity rating of CVE-2018-20732?
The severity rating of CVE-2018-20732 is 9.8 (Critical).
3
How does CVE-2018-20732 allow remote attackers to execute arbitrary code?
CVE-2018-20732 allows remote attackers to execute arbitrary code via a Java deserialization variant.
4
Which software versions are affected by CVE-2018-20732?
SAS Web Infrastructure Platform versions before 9.4M6 are affected by CVE-2018-20732.
5
How can I fix CVE-2018-20732?
To fix CVE-2018-20732, upgrade SAS Web Infrastructure Platform to version 9.4M6 or later.