SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 56560: SAS® Content Server is vulnerable to an XML external entity exploitation (CVE-2015-1833)

DetailsHotfixAboutRate It

Severity: Medium

Description: SAS Content Server is vulnerable to an XML external entity exploitation, as described in the Vulnerability Summary for CVE-2015-1833.

Potential Impact: An attacker might gain unauthorized access to files.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemSAS Release
ReportedFixed*
SAS SystemSAS Content ServerMicrosoft® Windows® for x649.3 TS1M09.4 TS1M4
Microsoft Windows Server 2003 Datacenter Edition9.3 TS1M0
Microsoft Windows Server 2003 Enterprise Edition9.3 TS1M0
Microsoft Windows Server 2003 Standard Edition9.3 TS1M0
Microsoft Windows Server 2003 for x649.3 TS1M0
Microsoft Windows Server 20089.3 TS1M09.4 TS1M4
Microsoft Windows Server 2008 R29.3 TS1M09.4 TS1M4
Microsoft Windows Server 2008 for x649.3 TS1M09.4 TS1M4
Microsoft Windows XP Professional9.3 TS1M0
Windows 7 Enterprise 32 bit9.3 TS1M09.4 TS1M4
Windows 7 Enterprise x649.3 TS1M09.4 TS1M4
Windows 7 Home Premium 32 bit9.3 TS1M09.4 TS1M4
Windows 7 Home Premium x649.3 TS1M09.4 TS1M4
Windows 7 Professional 32 bit9.3 TS1M09.4 TS1M4
Windows 7 Professional x649.3 TS1M09.4 TS1M4
Windows 7 Ultimate 32 bit9.3 TS1M09.4 TS1M4
Windows 7 Ultimate x649.3 TS1M09.4 TS1M4
Windows Vista9.3 TS1M0
Windows Vista for x649.3 TS1M0
Linux9.3 TS1M09.4 TS1M4
Linux for x649.3 TS1M09.4 TS1M4
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.