Problem Note 64613: SAS® Drive has a cross-site scripting vulnerability in the folder name and shortcut name fields
Severity: Medium
Description: SAS Drive might allow injection of malicious scripts into the folder name and shortcut name fields.
Potential Impact: Malicious code might be executed if users click on a URL that has been specially crafted by an attacker.
Click the Hot Fix tab in this note for a link to instructions about accessing and applying the software update.
Operating System and Release Information
SAS System | SAS Drive | Linux for x64 | 1.2.0 | 2.1 | Viya | Viya |
Microsoft® Windows® for x64 | 1.2.0 | 2.1 | Viya | Viya |
*
For software releases that are not yet generally available, the Fixed
Release is the software release in which the problem is planned to be
fixed.
Type: | Problem Note |
Priority: | high |
Date Modified: | 2019-09-16 15:10:48 |
Date Created: | 2019-08-13 14:47:00 |