Problem Note 63030: SAS® Customer Intelligence Studio contains a security vulnerability with attachments
Severity: Medium
Description: SAS Customer Intelligence Studio contains a security vulnerability with attachments.
Potential Impact: An attacker might be able to upload malicious files by using the attachments functionality in SAS® Marketing Automation, SAS® Marketing Optimization, and SAS® Digital Marketing.
Click the Hot Fix tab in this note to access the hot fix for this issue.
If you want to disable the attachments functionality after you apply the hot fix, add the following server property to the setenv.sh or wrapper.conf file (as appropriate) that is used to start the server where SAS Customer Intelligence Studio is located (typically, SASServer6_1).
-Dsas.ci.disableAttachments
Also, prevent users from adding attachments within SAS Customer Intelligence Studio by setting the <turnAttachmentsOff>true</turnAttachmentsOff> property in the config.xml file, as as detailed in the section "Prevent Users from Adding Attachments" section of "Chapter 2: Administration" in the SAS Marketing Automation: Administrators Guide for your release.
Be aware that there is currently an unintended consequence of adding this new server property, as detailed in SAS Note 63298, "SAS® You receive an HTTP 500 error in SAS Customer Intelligence Studio when you try to create a PDF document for a campaign."
Operating System and Release Information
SAS System | SAS Customer Intelligence Studio | Microsoft® Windows® for x64 | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Microsoft Windows 8 Enterprise 32-bit | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Microsoft Windows 8 Enterprise x64 | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Microsoft Windows 8 Pro 32-bit | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Microsoft Windows 8 Pro x64 | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Microsoft Windows 8.1 Enterprise 32-bit | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Microsoft Windows 8.1 Enterprise x64 | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Microsoft Windows 8.1 Pro 32-bit | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Microsoft Windows 8.1 Pro x64 | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Microsoft Windows 10 | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Microsoft Windows Server 2008 | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Microsoft Windows Server 2008 R2 | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Microsoft Windows Server 2008 for x64 | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Microsoft Windows Server 2012 Datacenter | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Microsoft Windows Server 2012 R2 Datacenter | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Microsoft Windows Server 2012 R2 Std | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Microsoft Windows Server 2012 Std | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Windows 7 Enterprise 32 bit | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Windows 7 Enterprise x64 | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Windows 7 Home Premium 32 bit | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Windows 7 Home Premium x64 | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Windows 7 Professional 32 bit | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Windows 7 Professional x64 | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Windows 7 Ultimate 32 bit | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Windows 7 Ultimate x64 | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
64-bit Enabled AIX | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
64-bit Enabled Solaris | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
HP-UX IPF | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Linux for x64 | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
Solaris for x64 | 6.4 | 6.6 | 9.4 TS1M2 | 9.4 TS1M6 |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
Type: | Problem Note |
Priority: | medium |
Date Modified: | 2018-11-02 07:44:20 |
Date Created: | 2018-10-05 06:54:54 |