SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 56326: IBM Security AppScan might return a high-priority report "Reflected XSS method GET" in SAS® Workflow Administrator 1.4 and 1.4_M1

DetailsHotfixAboutRate It

Severity: Medium

Description: When you access the SAS Workflow Administrator web application, you might receive a high-priority Reflected XSS method GET report from security scanners such as IBM Security AppScan. This report indicates that you might have reflected cross-site scripting vulnerabilities that allow escape characters and active JavaScript to potentially be passed and processed on the server without sufficient control and filtering.

Potential Impact: Users might unknowingly execute malicious code.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Workflow AdministratorLinux for x641.41.49.4 TS1M29.4 TS1M2
Microsoft® Windows® for x641.41.49.4 TS1M29.4 TS1M2
HP-UX IPF1.41.49.4 TS1M29.4 TS1M2
64-bit Enabled AIX1.41.49.4 TS1M29.4 TS1M2
64-bit Enabled Solaris1.41.49.4 TS1M29.4 TS1M2
Solaris for x641.41.49.4 TS1M29.4 TS1M2
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.