CVE-2019-14678: XEE
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this SAS XML Mapper vulnerability?
The vulnerability ID for this SAS XML Mapper vulnerability is CVE-2019-14678.
What is the severity of CVE-2019-14678?
The severity of CVE-2019-14678 is critical, with a severity value of 10.
What is the affected software for CVE-2019-14678?
The affected software for CVE-2019-14678 includes SAS XML Mapper 9.45 and SAS Base SAS 9.4 TS1M6.
What are the potential attacks that can be leveraged by this vulnerability?
This vulnerability can be leveraged by malicious attackers for potential attacks such as Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and Potential Denial of Service.
Where can I find more information about CVE-2019-14678?
You can find more information about CVE-2019-14678 in the SAS Knowledge Base article at http://support.sas.com/kb/64/719.html and the disclosure on GitHub at https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-14678-Unsafe%20XML%20Parsing-SAS%20XML%20Mapper.