SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 62425: A cross-site scripting vulnerability exists in the SAS® BI Dashboard Adobe Flash component

DetailsHotfixAboutRate It

Severity: Medium

Description: The DashboardRuntime.swf component of SAS BI Dashboard contains a cross-site scripting vulnerability.

Potential Impact: An attacker can inject malicious code that, in turn, can be executed unknowingly by a user.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Web Infrastructure PlatformMicrosoft® Windows® for x649.49.4_M69.4 TS1M09.4 TS1M6
64-bit Enabled AIX9.49.4_M69.4 TS1M09.4 TS1M6
64-bit Enabled Solaris9.49.4_M69.4 TS1M09.4 TS1M6
HP-UX IPF9.49.4_M69.4 TS1M09.4 TS1M6
Linux for x649.49.4_M69.4 TS1M09.4 TS1M6
Solaris for x649.49.4_M69.4 TS1M09.4 TS1M6
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.