SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 60093: A cross-site scripting vulnerability has been identified in the modern version of SAS® Visual Analytics Viewer

DetailsHotfixAboutRate It

Severity: Medium

Description: A cross-site scripting vulnerability has been identified in the modern version of SAS Visual Analytics Viewer. As a workaround until this issue is addressed, individual users can select Classic in their Default Appearance settings. An administrator can also set a global property to force the use of the classic version. This global property overrides individual preferences. For information about how to set the global property, see the SAS® Visual Analytics Administration Guide.

Potential Impact: A user might unknowingly execute malicious code.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Visual AnalyticsMicrosoft® Windows® for x647.37.49.4 TS1M39.4 TS1M4
Linux for x647.37.49.4 TS1M39.4 TS1M4
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.