Back
CVE-2019-14678
CRITICAL
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by malicious attackers in multiple ways. Examples are Local File Reading, Out Of Band File Exfiltration, Server Side Request Forgery, and/or Potential Denial of Service attacks. This vulnerability also affects the XMLV2 LIBNAME engine when the AUTOMAP option is used.
Published: Nov 14, 2019
Modified: Jun 17, 2026
CWE-611
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected Products (2)
| Vendor | Product | Version |
|---|---|---|
| sas | xml_mapper | 9.45 |
| sas | base_sas | 9.4 |
GitHub Security Advisory GHSA-65vm-7c4g-83vm
SAS XML Mapper 9.45 has an XML External Entity (XXE) vulnerability that can be leveraged by...
References (4)
- http://support.sas.com/kb/64/719.html Vendor Advisory
- https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-14678-Unsafe%20XML%20Parsing-SAS%20XML%20Mapper Exploit, Third Party Advisory
- http://support.sas.com/kb/64/719.html Vendor Advisory
- https://github.com/DrunkenShells/Disclosures/tree/master/CVE-2019-14678-Unsafe%20XML%20Parsing-SAS%20XML%20Mapper Exploit, Third Party Advisory
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
2.95%
Top 14% most likely to be exploited
Threat Score
40.9 / 100
Data Sources
NVD
EPSS
GitHub