Vulnerability Description
Unrestricted file upload vulnerability in the image upload module in SAS Visual Analytics 6.4M1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sas | Visual Analytics | 6.4 |
References
- http://packetstormsecurity.com/files/127866/SAS-Visual-Analytics-6.4M1-Arbitrary
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95351
- http://packetstormsecurity.com/files/127866/SAS-Visual-Analytics-6.4M1-Arbitrary
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95351
FAQ
What is CVE-2014-5454?
CVE-2014-5454 is a vulnerability with a CVSS score of 6.0 (MEDIUM). Unrestricted file upload vulnerability in the image upload module in SAS Visual Analytics 6.4M1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable exten...
How severe is CVE-2014-5454?
CVE-2014-5454 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-5454?
Check the references section above for vendor advisories and patch information. Affected products include: Sas Visual Analytics.