CVE-2018-20732

SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.
References
Link Resource
https://support.sas.com/kb/63/391.html Vendor Advisory
http://www.securityfocus.com/bid/106648 Third Party Advisory VDB Entry
Configurations

Configuration 1


Information

Published : 2019-01-17 01:29

Updated : 2019-02-07 06:14


NVD link : CVE-2018-20732

Mitre link : CVE-2018-20732

Products Affected
No products.
CWE
CWE-502

Deserialization of Untrusted Data