Problem Note 62511: SAS® Environment Manager contains a stored cross-site scripting vulnerability
Severity: Low
Description: The web application might allow injection of malicious scripts into an input field within the user management area of the application, which is accessible only to administrators and authorized users.
Potential Impact: A user with administrative rights might unknowingly execute malicious code.
Click the Hot Fix tab in this note to access the hot fix for this issue.
Operating System and Release Information
SAS System | SAS Environment Manager | Microsoft® Windows® for x64 | 9.4 TS1M0 | 9.4 TS1M6 |
64-bit Enabled AIX | 9.4 TS1M0 | 9.4 TS1M6 |
64-bit Enabled Solaris | 9.4 TS1M0 | 9.4 TS1M6 |
HP-UX IPF | 9.4 TS1M0 | 9.4 TS1M6 |
Linux for x64 | 9.4 TS1M0 | 9.4 TS1M6 |
Solaris for x64 | 9.4 TS1M0 | 9.4 TS1M6 |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
Type: | Problem Note |
Priority: | high |
Date Modified: | 2018-08-29 13:28:53 |
Date Created: | 2018-06-25 10:55:15 |