Vulnerability Description
BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.
CVSS Score
7.5
HIGH
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sas | Web Infrastructure Platform | < 9.4 |
| Hpe | Hp-Ux Ipfilter | - |
| Ibm | Aix | - |
| Linux | Linux Kernel | - |
| Microsoft | Windows | - |
| Oracle | Solaris | - |
Related Weaknesses (CWE)
References
- http://support.sas.com/kb/62/987.htmlPatchVendor Advisory
- http://support.sas.com/kb/62/987.htmlPatchVendor Advisory
FAQ
What is CVE-2018-20733?
CVE-2018-20733 is a vulnerability with a CVSS score of 7.5 (HIGH). BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.
How severe is CVE-2018-20733?
CVE-2018-20733 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-20733?
Check the references section above for vendor advisories and patch information. Affected products include: Sas Web Infrastructure Platform, Hpe Hp-Ux Ipfilter, Ibm Aix, Linux Linux Kernel, Microsoft Windows.