PT-2024-33193 · Sas · Sas Studio

Published

2024-10-30

·

Updated

2024-11-04

·

CVE-2024-48733

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAS Studio version 9.4
Description A SQL injection issue exists in the /SASStudio/sasexec/sessions/{sessionID}/sql endpoint of SAS Studio, allowing a remote attacker to execute arbitrary SQL commands via the POST body request. This issue is disputed by the vendor as SQL statement execution is intended for authorized users.
Recommendations For SAS Studio version 9.4, consider restricting access to the /SASStudio/sasexec/sessions/{sessionID}/sql endpoint to minimize the risk of exploitation. As a temporary workaround, limit the execution of SQL commands to only necessary and authorized users until a patch or official guidance is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-48733

Affected Products

Sas Studio