CVE-2018-20733: Sas Web Infrastructure Platform

High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.

BI Web Services in SAS Web Infrastructure Platform before 9.4M6 allows XXE.

Affected products

  • Sas Web Infrastructure Platform: before 9.4 (fixed in 9.4); version 9.4 only

Published 2019-01-17. Last modified 2026-06-17.