CVE: CVE-2002-2017

Export to Word

sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd.

Threat-Mapped Scoring

Score: 1.8

Priority: P4 - Informational (Low)

EPSS

Score: 0.00642
Percentile: 0.69642

CVSS Scoring

CVSS v2 Score: 10.0

Severity:

Affected Products

← Back to Home