Problem Note 58692: SAS® Web Report Studio is vulnerable to a cross-site scripting variant
Severity: Medium
Description: SAS Web Report Studio has a vulnerability to a variant of cross-site scripting.
Potential Impact: Users might unknowingly execute malicious code.
Click the Hot Fix tab in this note to access the hot fix for this issue.
Operating System and Release Information
| SAS System | SAS Web Report Studio | Microsoft® Windows® for x64 | 4.3 | 4.4_M2 | 9.2 TS2M3 | 9.4 TS1M2 |
| Microsoft Windows Server 2003 Datacenter Edition | 4.3 | | 9.2 TS2M3 | |
| Microsoft Windows Server 2003 Enterprise Edition | 4.3 | | 9.2 TS2M3 | |
| Microsoft Windows Server 2003 Standard Edition | 4.3 | | 9.2 TS2M3 | |
| Microsoft Windows Server 2003 for x64 | 4.3 | | 9.2 TS2M3 | |
| Microsoft Windows Server 2008 | 4.3 | 4.4_M2 | 9.2 TS2M3 | 9.4 TS1M2 |
| Microsoft Windows Server 2008 R2 | 4.3 | 4.4_M2 | 9.2 TS2M3 | 9.4 TS1M2 |
| Microsoft Windows Server 2008 for x64 | 4.3 | 4.4_M2 | 9.2 TS2M3 | 9.4 TS1M2 |
| Microsoft Windows XP Professional | 4.3 | | 9.2 TS2M3 | |
| Windows 7 Enterprise 32 bit | 4.3 | 4.4_M2 | 9.2 TS2M3 | 9.4 TS1M2 |
| Windows 7 Enterprise x64 | 4.3 | 4.4_M2 | 9.2 TS2M3 | 9.4 TS1M2 |
| Windows 7 Home Premium 32 bit | 4.3 | 4.4_M2 | 9.2 TS2M3 | 9.4 TS1M2 |
| Windows 7 Home Premium x64 | 4.3 | 4.4_M2 | 9.2 TS2M3 | 9.4 TS1M2 |
| Windows 7 Professional 32 bit | 4.3 | 4.4_M2 | 9.2 TS2M3 | 9.4 TS1M2 |
| Windows 7 Professional x64 | 4.3 | 4.4_M2 | 9.2 TS2M3 | 9.4 TS1M2 |
| Windows 7 Ultimate 32 bit | 4.3 | 4.4_M2 | 9.2 TS2M3 | 9.4 TS1M2 |
| Windows 7 Ultimate x64 | 4.3 | 4.4_M2 | 9.2 TS2M3 | 9.4 TS1M2 |
| Windows Vista | 4.3 | | 9.2 TS2M3 | |
| Windows Vista for x64 | 4.3 | | 9.2 TS2M3 | |
| 64-bit Enabled AIX | 4.3 | 4.4_M2 | 9.2 TS2M3 | 9.4 TS1M2 |
| 64-bit Enabled Solaris | 4.3 | 4.4_M2 | 9.2 TS2M3 | 9.4 TS1M2 |
| HP-UX IPF | 4.3 | 4.4_M2 | 9.2 TS2M3 | 9.4 TS1M2 |
| Linux for x64 | 4.3 | 4.4_M2 | 9.2 TS2M3 | 9.4 TS1M2 |
| Solaris for x64 | 4.3 | 4.4_M2 | 9.2 TS2M3 | 9.4 TS1M2 |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
| Type: | Problem Note |
| Priority: | high |
| Date Modified: | 2016-07-28 13:37:35 |
| Date Created: | 2016-07-28 13:04:31 |