SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 59507: The GetObjectPropertyBySuperUser function in SAS® Model Risk Management contains a security vulnerability

DetailsHotfixAboutRate It

In SAS Model Risk Management, the C_GetObjectPropertyBySuperUser custom function might contain an access-control security vulnerability.

To prevent this security issue, use the following new function in the screen definition file instead of the C_GetObjectPropertyBySuperUser function:

getModelRiskAssessmentRiskValues()

There are no parameters for the new function.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Model Risk Management64-bit Enabled Solaris7.17.29.4 TS1M39.4 TS1M4
HP-UX IPF7.17.29.4 TS1M39.4 TS1M4
Linux for x647.17.29.4 TS1M39.4 TS1M4
Solaris for x647.17.29.4 TS1M39.4 TS1M4
64-bit Enabled AIX7.17.29.4 TS1M39.4 TS1M4
Windows 7 Ultimate x647.17.29.4 TS1M39.4 TS1M4
Windows 7 Ultimate 32 bit7.17.29.4 TS1M39.4 TS1M4
Windows 7 Professional x647.17.29.4 TS1M39.4 TS1M4
Windows 7 Professional 32 bit7.17.29.4 TS1M39.4 TS1M4
Windows 7 Home Premium x647.17.29.4 TS1M39.4 TS1M4
Windows 7 Home Premium 32 bit7.17.29.4 TS1M39.4 TS1M4
Windows 7 Enterprise x647.17.29.4 TS1M39.4 TS1M4
Windows 7 Enterprise 32 bit7.17.29.4 TS1M39.4 TS1M4
Microsoft Windows Server 2012 Std7.17.29.4 TS1M39.4 TS1M4
Microsoft Windows Server 2012 R2 Std7.17.29.4 TS1M39.4 TS1M4
Microsoft Windows Server 2012 R2 Datacenter7.17.29.4 TS1M39.4 TS1M4
Microsoft Windows Server 2012 Datacenter7.17.29.4 TS1M39.4 TS1M4
Microsoft Windows Server 2008 for x647.17.29.4 TS1M39.4 TS1M4
Microsoft Windows Server 2008 R27.17.29.4 TS1M39.4 TS1M4
Microsoft Windows Server 20087.17.29.4 TS1M39.4 TS1M4
Microsoft Windows 107.17.29.4 TS1M39.4 TS1M4
Microsoft Windows 8.1 Pro x647.17.29.4 TS1M39.4 TS1M4
Microsoft Windows 8.1 Pro 32-bit7.17.29.4 TS1M39.4 TS1M4
Microsoft Windows 8.1 Enterprise x647.17.29.4 TS1M39.4 TS1M4
Microsoft Windows 8.1 Enterprise 32-bit7.17.29.4 TS1M39.4 TS1M4
Microsoft Windows 8 Pro x647.17.29.4 TS1M39.4 TS1M4
Microsoft Windows 8 Pro 32-bit7.17.29.4 TS1M39.4 TS1M4
Microsoft Windows 8 Enterprise x647.17.29.4 TS1M39.4 TS1M4
Microsoft Windows 8 Enterprise 32-bit7.17.29.4 TS1M39.4 TS1M4
Microsoft® Windows® for x647.17.29.4 TS1M39.4 TS1M4
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.