Back

CVE-2019-14678

CRITICAL

SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.

Published: Nov 14, 2019 Modified: Jun 17, 2026
CWE-611

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products (2)

Vendor Product Version
sas xml_mapper 9.45
sas base_sas 9.4

GitHub Security Advisory GHSA-65vm-7c4g-83vm

SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 2.95%

Top 14% most likely to be exploited

Threat Score 40.9 / 100

Data Sources

NVD EPSS GitHub