Severity: High
Description: The Export to Excel feature of the web application might enable injection of malicious scripts into a cell of a Microsoft Excel spreadsheet.
Potential Impact: Users might unknowingly execute malicious code.
Click the Hot Fix tab in this note to access the hot fix for this issue.
With this fix, the web application escapes the text for any cell whose value begins with one of the following characters:
After you install the hot fix, you can specify additional characters to escape, by specifying the following configuration property in the configdata.properties file:
For example, if you would like to escape the # character, you would add the character to the list of default characters, as shown in the following example:
Product Family | Product | System | Product Release | SAS Release | ||
Reported | Fixed* | Reported | Fixed* | |||
SAS System | SAS Enterprise GRC | Microsoft Windows Server 2003 Standard Edition | 5.1_M5 | 9.3 TS1M2 | ||
Microsoft Windows Server 2003 for x64 | 5.1_M5 | 9.3 TS1M2 | ||||
Microsoft Windows Server 2008 | 5.1_M5 | 9.3 TS1M2 | ||||
Microsoft Windows Server 2008 R2 | 5.1_M5 | 9.3 TS1M2 | ||||
Microsoft Windows Server 2008 for x64 | 5.1_M5 | 9.3 TS1M2 | ||||
Microsoft Windows Server 2012 Datacenter | 5.1_M5 | 9.3 TS1M2 | ||||
Microsoft Windows Server 2012 R2 Datacenter | 5.1_M5 | 9.3 TS1M2 | ||||
Microsoft Windows Server 2012 R2 Std | 5.1_M5 | 9.3 TS1M2 | ||||
Microsoft Windows Server 2012 Std | 5.1_M5 | 9.3 TS1M2 | ||||
Microsoft Windows XP Professional | 5.1_M5 | 9.3 TS1M2 | ||||
Microsoft Windows Server 2003 Enterprise Edition | 5.1_M5 | 9.3 TS1M2 | ||||
Microsoft Windows Server 2003 Datacenter Edition | 5.1_M5 | 9.3 TS1M2 | ||||
Microsoft Windows 8.1 Pro x64 | 5.1_M5 | 9.3 TS1M2 | ||||
Microsoft Windows 8.1 Pro 32-bit | 5.1_M5 | 9.3 TS1M2 | ||||
Microsoft Windows 8.1 Enterprise x64 | 5.1_M5 | 9.3 TS1M2 | ||||
Microsoft Windows 8.1 Enterprise 32-bit | 5.1_M5 | 9.3 TS1M2 | ||||
Microsoft Windows 8 Pro x64 | 5.1_M5 | 9.3 TS1M2 | ||||
Microsoft Windows 8 Pro 32-bit | 5.1_M5 | 9.3 TS1M2 | ||||
Microsoft Windows 8 Enterprise x64 | 5.1_M5 | 9.3 TS1M2 | ||||
Microsoft Windows 8 Enterprise 32-bit | 5.1_M5 | 9.3 TS1M2 | ||||
Windows 7 Enterprise 32 bit | 5.1_M5 | 9.3 TS1M2 | ||||
Windows 7 Enterprise x64 | 5.1_M5 | 9.3 TS1M2 | ||||
Windows 7 Home Premium 32 bit | 5.1_M5 | 9.3 TS1M2 | ||||
Windows 7 Home Premium x64 | 5.1_M5 | 9.3 TS1M2 | ||||
Windows 7 Professional 32 bit | 5.1_M5 | 9.3 TS1M2 | ||||
Windows 7 Professional x64 | 5.1_M5 | 9.3 TS1M2 | ||||
Windows 7 Ultimate 32 bit | 5.1_M5 | 9.3 TS1M2 | ||||
Windows 7 Ultimate x64 | 5.1_M5 | 9.3 TS1M2 | ||||
Microsoft® Windows® for x64 | 5.1_M5 | 9.3 TS1M2 | ||||
Windows Vista | 5.1_M5 | 9.3 TS1M2 | ||||
Windows Vista for x64 | 5.1_M5 | 9.3 TS1M2 | ||||
64-bit Enabled AIX | 5.1_M5 | 9.3 TS1M2 | ||||
64-bit Enabled Solaris | 5.1_M5 | 9.3 TS1M2 | ||||
HP-UX IPF | 5.1_M5 | 9.3 TS1M2 | ||||
Linux for x64 | 5.1_M5 | 9.3 TS1M2 | ||||
Solaris for x64 | 5.1_M5 | 9.3 TS1M2 | ||||
SAS System | SAS Model Risk Management | Microsoft® Windows® for x64 | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 |
Microsoft Windows 8 Enterprise 32-bit | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Microsoft Windows 8 Enterprise x64 | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Microsoft Windows 8 Pro 32-bit | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Microsoft Windows 8 Pro x64 | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Microsoft Windows 8.1 Enterprise 32-bit | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Microsoft Windows 8.1 Enterprise x64 | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Microsoft Windows 8.1 Pro 32-bit | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Microsoft Windows 8.1 Pro x64 | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Microsoft Windows 10 | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Microsoft Windows Server 2008 | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Microsoft Windows Server 2008 R2 | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Microsoft Windows Server 2008 for x64 | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Microsoft Windows Server 2012 Datacenter | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Microsoft Windows Server 2012 R2 Datacenter | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Microsoft Windows Server 2012 R2 Std | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Microsoft Windows Server 2012 Std | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Windows 7 Enterprise 32 bit | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Windows 7 Enterprise x64 | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Windows 7 Home Premium 32 bit | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Windows 7 Home Premium x64 | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Windows 7 Professional 32 bit | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Windows 7 Professional x64 | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Windows 7 Ultimate 32 bit | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Windows 7 Ultimate x64 | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
64-bit Enabled AIX | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
64-bit Enabled Solaris | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
HP-UX IPF | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Linux for x64 | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 | ||
Solaris for x64 | 6.1 | 7.4 | 9.4 TS1M2 | 9.4 TS1M5 |
A fix for this issue for SAS Risk Governance Framework 7.3 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/C2I.html#61916A fix for this issue for SAS Model Risk Management 7.3 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/C3S.html#61916A fix for this issue for SAS Model Risk Management 7.2 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/A4V.html#61916A fix for this issue for SAS Model Risk Management 7.1 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/Z95.html#61916A fix for this issue for SAS Model Risk Management 6.1 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/W72.html#61916A fix for this issue for SAS Enterprise GRC 6.1 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/T04.html#61916A fix for this issue for SAS Enterprise GRC 5.1_M5 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/P04.html#61916A fix for this issue for SAS Enterprise GRC 5.1_M5 is available at:
https://tshf.sas.com/techsup/download/hotfix/HF2/P04.html#61916Type: | Problem Note |
Priority: | high |
Date Modified: | 2019-03-22 09:34:22 |
Date Created: | 2018-03-01 09:58:49 |