SAS/ACCESS® Interface to Snowflake allows the bypassing of LOCKDOWN restrictions


Severity: Critical

Description: SAS/ACCESS Interface to Snowflake gives the ability to access files and bypass LOCKDOWN restrictions to a user via the LIBNAME statement

Potential Impact: An attacker can upload or download files.

After applying the hot fix, an error similar to the following occurs when attempting to upload or download a file:

ERROR: The DBMS connection failed. The DBCONINIT=<command> option failed with this message: GET/PUT operations are rejected in explicit passthru.