CVE-2023-4932 - CVE House
Back to Database
Status published Medium CVE-2023-4932

Reflected Cross-Site Scripting in SAS 9.4

Vulnerability Description

SAS application is vulnerable to Reflected Cross-Site Scripting (XSS). Improper input validation in the `_program` parameter of the the `/SASStoredProcess/do` endpoint allows arbitrary JavaScript to be executed when specially crafted URL is opened by an authenticated user. The attack is possible from a low-privileged user. Only versions 9.4_M7 and 9.4_M8 were tested and confirmed to be vulnerable, status of others is unknown. For above mentioned versions hot fixes were published.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-4932

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Sławomir Zakrzewski, Maksymilian Kubiak [AFINE Team]

Affected Vendor

SAS Institute

View all reports →

Affected Software

SAS Integration Technologies
Vulnerable Versions:
9.4_M7

Timeline

Official Publish: December 12th, 2023
Last Modified: August 2nd, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:L

Weaknesses (CWE)