Critical severity9.8NVD Advisory· Published Jan 17, 2019· Updated Jun 17, 2026
CVE-2018-20732
CVE-2018-20732
Description
SAS Web Infrastructure Platform before 9.4M6 allows remote attackers to execute arbitrary code via a Java deserialization variant.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:sas:web_infrastructure_platform:*:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:sas:web_infrastructure_platform:*:*:*:*:*:*:*:*range: <9.4
- cpe:2.3:a:sas:web_infrastructure_platform:9.4:-:*:*:*:*:*:*
- cpe:2.3:a:sas:web_infrastructure_platform:9.4:maintenance_release_1:*:*:*:*:*:*
- cpe:2.3:a:sas:web_infrastructure_platform:9.4:maintenance_release_2:*:*:*:*:*:*
- cpe:2.3:a:sas:web_infrastructure_platform:9.4:maintenance_release_3:*:*:*:*:*:*
- cpe:2.3:a:sas:web_infrastructure_platform:9.4:maintenance_release_4:*:*:*:*:*:*
- cpe:2.3:a:sas:web_infrastructure_platform:9.4:maintenance_release_5:*:*:*:*:*:*
- (no CPE)range: <9.4M6
Patches
Vulnerability mechanics
References
2- www.securityfocus.com/bid/106648nvdThird Party AdvisoryVDB Entry
- support.sas.com/kb/63/391.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.