SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 63100: SAS® Visual Analytics contains a cross-site scripting vulnerability related to request headers

DetailsHotfixAboutRate It

Severity: Medium

Description: A malicious script can be injected into a request header, and returned back to the browser in an error response from SAS Visual Analytics.

Potential Impact: Users might unknowingly execute malicious code.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Visual AnalyticsLinux for x647.37.59.4 TS1M39.4 TS1M6
Microsoft® Windows® for x647.37.59.4 TS1M39.4 TS1M6
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.