PT-2024-33193 · Sas · Sas Studio
Published
2024-10-30
·
Updated
2024-11-04
·
CVE-2024-48733
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAS Studio version 9.4
Description
A SQL injection issue exists in the /SASStudio/sasexec/sessions/{sessionID}/sql endpoint of SAS Studio, allowing a remote attacker to execute arbitrary SQL commands via the POST body request. This issue is disputed by the vendor as SQL statement execution is intended for authorized users.
Recommendations
For SAS Studio version 9.4, consider restricting access to the /SASStudio/sasexec/sessions/{sessionID}/sql endpoint to minimize the risk of exploitation. As a temporary workaround, limit the execution of SQL commands to only necessary and authorized users until a patch or official guidance is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sas Studio