![]() | ![]() | ![]() | ![]() | ![]() |
Severity: Medium
Description: Applications that use the comments service contain a security vulnerability with the use of comments.
Potential Impact: An attacker might be able to forge comments.
Click the Hot Fix tab in this note to access the hot fix for this issue.
After you apply the hot fix, you can prevent forgery of comments by adding the following server property to the setenv.sh file or wrapper.conf file (as appropriate) that is used to start the server where the SAS Web Infrastructure Platform is located (typically, SASServer1_1).
Notes:
Product Family | Product | System | Product Release | SAS Release | ||
Reported | Fixed* | Reported | Fixed* | |||
SAS System | SAS Web Infrastructure Platform | Solaris for x64 | 9.4_M2 | 9.4_M6 | 9.4 TS1M2 | 9.4 TS1M6 |
Linux for x64 | 9.4_M2 | 9.4_M6 | 9.4 TS1M2 | 9.4 TS1M6 | ||
HP-UX IPF | 9.4_M2 | 9.4_M6 | 9.4 TS1M2 | 9.4 TS1M6 | ||
64-bit Enabled Solaris | 9.4_M2 | 9.4_M6 | 9.4 TS1M2 | 9.4 TS1M6 | ||
64-bit Enabled AIX | 9.4_M2 | 9.4_M6 | 9.4 TS1M2 | 9.4 TS1M6 | ||
Microsoft® Windows® for x64 | 9.4_M2 | 9.4_M6 | 9.4 TS1M2 | 9.4 TS1M6 |