SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 63306: Use of the SAS/GRAPH® Java device driver or the Java-based graph macros (such as the DS2TREE macro) might result in a security vulnerability issue

DetailsHotfixAboutRate It

Severity: Medium

Description: Use of the SAS/GRAPH Java device driver or any of the Java-based graph macros (such as the DS2TREE macro) might result in a security vulnerability issue. This issue can occur due to the resulting HTML output that attempts to load a JavaScript file via http://www.java.com.   

Potential Impact: A compromise of the third-party JavaScript server and the injection of malicious JavaScript into the original JavaScript.

To circumvent the issue when you use the Java device driver, switch to a different device driver (such as PNG, ACTIVEX, or JAVAIMG).       

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS/GRAPHz/OS9.49.4_M69.4 TS1M09.4 TS1M6
Microsoft® Windows® for x649.49.4_M69.4 TS1M09.4 TS1M6
Microsoft Windows 8 Enterprise x649.49.4_M69.4 TS1M09.4 TS1M6
Microsoft Windows 8 Pro x649.49.4_M69.4 TS1M09.4 TS1M6
Microsoft Windows 8.1 Enterprise 32-bit9.49.4_M69.4 TS1M09.4 TS1M6
Microsoft Windows 8.1 Enterprise x649.49.4_M69.4 TS1M09.4 TS1M6
Microsoft Windows 8.1 Pro 32-bit9.49.4_M69.4 TS1M09.4 TS1M6
Microsoft Windows 8.1 Pro x649.49.4_M69.4 TS1M09.4 TS1M6
Microsoft Windows 109.49.4_M69.4 TS1M09.4 TS1M6
Microsoft Windows Server 2008 R29.49.4 TS1M0
Microsoft Windows Server 2008 for x649.49.4 TS1M0
Microsoft Windows Server 2012 Datacenter9.49.4_M69.4 TS1M09.4 TS1M6
Microsoft Windows Server 2012 R2 Datacenter9.49.4_M69.4 TS1M09.4 TS1M6
Microsoft Windows Server 2012 R2 Std9.49.4_M69.4 TS1M09.4 TS1M6
Microsoft Windows Server 2012 Std9.49.4_M69.4 TS1M09.4 TS1M6
Windows 7 Enterprise x649.49.4_M69.4 TS1M09.4 TS1M6
Windows 7 Professional x649.49.4_M69.4 TS1M09.4 TS1M6
64-bit Enabled AIX9.49.4_M69.4 TS1M09.4 TS1M6
64-bit Enabled Solaris9.49.4_M69.4 TS1M09.4 TS1M6
HP-UX IPF9.49.4_M69.4 TS1M09.4 TS1M6
Linux for x649.49.4_M69.4 TS1M09.4 TS1M6
Solaris for x649.49.4_M69.4 TS1M09.4 TS1M6
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.