SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 63844: Application parameters are not sanitized in SAS® Web Report Studio

DetailsHotfixAboutRate It

Severity: Medium

Description: Application parameters are not sanitized or validated in SAS Web Report Studio. This behavior might allow a reflected cross-site scripting (XSS) vulnerability to exist.

Potential Impact: HTML or JavaScript code can be injected into a web page.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Web Report StudioMicrosoft® Windows® for x644.4_M64.4_M79.4 TS1M69.4 TS1M7
64-bit Enabled AIX4.4_M64.4_M79.4 TS1M69.4 TS1M7
64-bit Enabled Solaris4.4_M64.4_M79.4 TS1M69.4 TS1M7
HP-UX IPF4.4_M64.4_M79.4 TS1M69.4 TS1M7
Linux for x644.4_M64.4_M79.4 TS1M69.4 TS1M7
Solaris for x644.4_M64.4_M79.4 TS1M69.4 TS1M7
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.