SAS/ACCESS® Interface to PostgreSQL and SAS/ACCESS® Interface Yellowbrick contain an OS command injection vulnerability


Severity: Critical

Description: The bulkloading functionality for SAS/ACCESS Interface to PostgreSQL and SAS/ACCESS Interface to Yellowbrick might allow OS command execution on the compute server, bypassing LOCKDOWN restrictions. 

Potential Impact: A user might execute unauthorized OS commands on the compute server.