Studio
Sas · 3 CVEs
CVE-2024-48735
HIGH
Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote…
Oct 30, 2024
CVE-2024-48734
HIGH
Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote att…
Oct 30, 2024
CVE-2024-48733
HIGH
SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to…
Oct 30, 2024
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-48735 | Directory Traversal in /SASStudio/sasexec/sessions/{sessionID}/workspace/{InternalPath} in SAS Studio 9.4 allows remote attacker to access internal files by ma… | HIGH | 0.97% | Oct 30, 2024 |
| CVE-2024-48734 | Unrestricted file upload in /SASStudio/SASStudio/sasexec/{sessionID}/{InternalPath} in SAS Studio 9.4 allows remote attacker to upload malicious files. NOTE: t… | HIGH | 0.62% | Oct 30, 2024 |
| CVE-2024-48733 | SQL injection vulnerability in /SASStudio/sasexec/sessions/{sessionID}/sql in SAS Studio 9.4 allows remote attacker to execute arbitrary SQL commands via the P… | HIGH | 0.73% | Oct 30, 2024 |
Showing 1 to 3 of 3 CVEs