CVE-2023-4932
Reflected Cross-Site Scripting in SAS 9.4
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SAS application is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in the `_program` parameter of the the `/SASStoredProcess/do` endpoint allows arbitrary JavaScript to be executed when specially crafted URL is opened by an authenticated user. The attack is possible from a low-privileged user. Only versions 9.4_M7 and 9.4_M8 were tested and confirmed to be vulnerable, status of others is unknown. For above mentioned versions hot fixes were published.
La aplicación SAS es vulnerable a Cross-Site Scripting (XSS) Reflejado. La validación de entrada incorrecta en el parámetro `_program` del endpoint `/SASStoredProcess/do` permite que se ejecute JavaScript arbitrario cuando un usuario autenticado abre una URL especialmente manipulada. El ataque es posible por parte de un usuario con pocos privilegios. Solo se probaron las versiones 9.4_M7 y 9.4_M8 y se confirmó que eran vulnerables; se desconoce el estado de las demás. Para las versiones mencionadas anteriormente se publicaron revisiones.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-09-13 CVE Reserved
- 2023-12-12 CVE Published
- 2024-08-02 CVE Updated
- 2024-11-11 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
- CAPEC-591: Reflected XSS
References (3)
URL | Tag | Source |
---|---|---|
https://cert.pl/en/posts/2023/12/CVE-2023-4932 | Third Party Advisory | |
https://cert.pl/posts/2023/12/CVE-2023-4932 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://support.sas.com/kb/70/265.html | 2023-12-15 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sas Search vendor "Sas" | Integration Technologies Search vendor "Sas" for product "Integration Technologies" | 9.4 Search vendor "Sas" for product "Integration Technologies" and version "9.4" | m7 |
Affected
| ||||||
Sas Search vendor "Sas" | Integration Technologies Search vendor "Sas" for product "Integration Technologies" | 9.4 Search vendor "Sas" for product "Integration Technologies" and version "9.4" | m8 |
Affected
|