CVE-2018-20733: XEE
Published Jan 17, 2019
·Updated
BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.
Affected Software
12 affected components
SAS Web Infrastructure Platform<9.4
SAS Web Infrastructure Platform=9.4
SAS Web Infrastructure Platform=9.4-maintenance_release_1
SAS Web Infrastructure Platform=9.4-maintenance_release_2
SAS Web Infrastructure Platform=9.4-maintenance_release_3
SAS Web Infrastructure Platform=9.4-maintenance_release_4
SAS Web Infrastructure Platform=9.4-maintenance_release_5
HPE Hp-ux Ipfilter
IBM AIX
Linux Linux kernel
Microsoft Windows
Oracle Solaris
Remediation
Patch Available
Event History
Jan 17, 2019
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2018-20733.
2
What is the title of this vulnerability?
The title of this vulnerability is BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.
3
What is the severity rating of CVE-2018-20733?
CVE-2018-20733 has a severity rating of 7.5 (high).
4
Which software versions are affected by CVE-2018-20733?
BI Web Services in SAS Web Infrastructure Platform versions before 9.4M6 are affected by CVE-2018-20733.
5
How can I fix the vulnerability CVE-2018-20733?
To fix the vulnerability CVE-2018-20733, update your SAS Web Infrastructure Platform to version 9.4M6 or later.