SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 64613: SAS® Drive has a cross-site scripting vulnerability in the folder name and shortcut name fields

DetailsHotfixAboutRate It

Severity: Medium

Description: SAS Drive might allow injection of malicious scripts into the folder name and shortcut name fields.

Potential Impact: Malicious code might be executed if users click on a URL that has been specially crafted by an attacker.

Click the Hot Fix tab in this note for a link to instructions about accessing and applying the software update.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS DriveLinux for x641.2.02.1ViyaViya
Microsoft® Windows® for x641.2.02.1ViyaViya
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.