SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 61880: The SAS® 9.4 Logon Manager time-out page is vulnerable to injection of HTML code

DetailsHotfixAboutRate It

Severity: High

Description: It is possible to inject HTML code into a URL that is sent to SAS 9.4 Logon Manager in such a way that the code is rendered in the HTTP response. 

Potential Impact:  An attacker can modify the web page that is viewed by the user, allowing the potential for a variety of malicious exploits.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Web Infrastructure PlatformMicrosoft® Windows® for x649.49.4_M59.4 TS1M09.4 TS1M5
64-bit Enabled AIX9.49.4_M59.4 TS1M09.4 TS1M5
64-bit Enabled Solaris9.49.4_M59.4 TS1M09.4 TS1M5
HP-UX IPF9.49.4_M59.4 TS1M09.4 TS1M5
Linux for x649.49.4_M59.4 TS1M09.4 TS1M5
Solaris for x649.49.4_M59.4 TS1M09.4 TS1M5
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.