SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 62494: SAS® Visual Analytics contains an XML External Entity (XXE) vulnerability

DetailsHotfixAboutRate It

Severity: High

Description: The SAS Visual Analytics application accepts XML documents and processes external entities defined therein, within the View Report area of the application.

Potential Impact: This vulnerability might be exploited to gain unauthorized access to files on the file system or to perform a Denial of Service attack.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Visual AnalyticsMicrosoft® Windows® for x647.48.3Viya
Linux for x647.48.3Viya
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.