SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 62039: Lack of URL sanitization in SAS® Contextual Analysis

DetailsHotfixAboutRate It

Title: Lack of URL sanitization in SAS Contextual Analysis

Severity: Medium

Description: SAS Contextual Analysis URL accepts JavaScript code as a parameter, and executes the JavaScript code on the browser.

Potential Impact: You might unknowingly execute malicious code.

 

Click the Hot Fix tab in this note to access the hot fix for this issue.

 



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Contextual AnalysisMicrosoft® Windows® for x6414.29.4 TS1M4
64-bit Enabled AIX14.29.4 TS1M4
64-bit Enabled Solaris14.29.4 TS1M4
HP-UX IPF14.29.4 TS1M4
Linux for x6414.29.4 TS1M4
Solaris for x6414.29.4 TS1M4
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.