SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 64903: SAS® Information Delivery Portal contains a directory-traversal vulnerability

DetailsHotfixAboutRate It

Severity: Low

Description: A vulnerability exists in SAS® Information Delivery Portal that allows an attacker to perform a directory-traversal attack.

Potential Impact: Potentially, an attacker can leverage this vulnerability to facilitate an information-disclosure attack.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemSAS Release
ReportedFixed*
SAS SystemSAS Web Application ServerSolaris for x649.4 TS1M59.4 TS1M5
Linux for x649.4 TS1M59.4 TS1M5
HP-UX IPF9.4 TS1M59.4 TS1M5
64-bit Enabled Solaris9.4 TS1M59.4 TS1M5
64-bit Enabled AIX9.4 TS1M59.4 TS1M5
Microsoft® Windows® for x649.4 TS1M59.4 TS1M5
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.