CVE-2024-48735: Path Traversal
Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote attacker to access internal files by manipulating default path during file download. NOTE: this is disputed by the vendor because these filesystem paths are allowed for authorized users.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-48735?
CVE-2024-48735 has been evaluated as a significant vulnerability due to its potential for unauthorized access to internal files.
How do I fix CVE-2024-48735?
To address CVE-2024-48735, ensure that file access permissions are properly configured and restrict the ability to manipulate file paths.
Which versions of SAS Studio are affected by CVE-2024-48735?
CVE-2024-48735 affects SAS Studio 9.4.
Can CVE-2024-48735 be exploited remotely?
Yes, CVE-2024-48735 can be exploited remotely by an attacker to access restricted files.
Is the impact of CVE-2024-48735 disputed by the vendor?
Yes, SAS has disputed the impact of CVE-2024-48735, stating that the filesystem paths are only accessible to authorized users.