SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 34727: Users of SAS® Credit Risk Studio might be able to access server files without being granted permissions

DetailsHotfixAboutRate It

Users of SAS Credit Risk Studio might be able to access server files without explicitly being granted permissions to do so.

For example, criskuser1 and criskuser2 are SAS Credit Risk Studio users that have not been granted permission to view one another's files on the SAS® Credit Risk Management for Banking Server. User criskuser1 should not be able to access criskuser2 server files. However, by exploiting the SAS Credit Risk Studio file servlet, criskuser1 might be able to access the criskuser2 server files that are associated with a given URL.

Select the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Credit Risk Management for BankingMicrosoft Windows Server 2003 Standard Edition4.54.69.1 TS1M3 SP49.2 TS2M2
Microsoft Windows XP Professional4.54.69.1 TS1M3 SP49.2 TS2M2
Windows Vista4.54.69.1 TS1M3 SP49.2 TS2M2
Windows Vista for x644.54.69.1 TS1M3 SP49.2 TS2M2
Microsoft Windows Server 2003 Enterprise Edition4.54.69.1 TS1M3 SP49.2 TS2M2
Microsoft Windows Server 2003 Datacenter Edition4.54.69.1 TS1M3 SP49.2 TS2M2
Microsoft Windows NT Workstation4.59.1 TS1M3 SP4
Microsoft Windows 2000 Professional4.59.1 TS1M3 SP4
Microsoft Windows 2000 Server4.59.1 TS1M3 SP4
Microsoft Windows 2000 Datacenter Server4.59.1 TS1M3 SP4
Microsoft Windows 2000 Advanced Server4.59.1 TS1M3 SP4
64-bit Enabled AIX4.54.69.1 TS1M3 SP49.2 TS2M2
64-bit Enabled HP-UX4.54.69.1 TS1M3 SP49.2 TS2M2
64-bit Enabled Solaris4.54.69.1 TS1M3 SP49.2 TS2M2
HP-UX IPF4.54.69.1 TS1M3 SP49.2 TS2M2
Linux4.54.69.1 TS1M3 SP49.2 TS2M2
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.