SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 62573: SAS® BI portlets are vulnerable to arbitrary URL redirection

DetailsHotfixAboutRate It

Severity: Medium

Description: The web application allows redirection to arbitrary web sites via URL manipulation.

Potential Impact: Users might unknowingly be redirected to a malicious web site.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS BI PortletsMicrosoft® Windows® for x644.44.4_M59.4 TS1M09.4 TS1M5
64-bit Enabled AIX4.44.4_M59.4 TS1M09.4 TS1M5
64-bit Enabled Solaris4.44.4_M59.4 TS1M09.4 TS1M5
HP-UX IPF4.44.4_M59.4 TS1M09.4 TS1M5
Linux for x644.44.4_M59.4 TS1M09.4 TS1M5
Solaris for x644.44.4_M59.4 TS1M09.4 TS1M5
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.