SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 65358: SAS® Graph Builder contains a cross-site scripting vulnerability

DetailsHotfixAboutRate It

Severity: Low

Description: An authenticated user can store a graph template containing malicious Javascript.

Potential Impact: If a user accesses the graph template directly (outside of SAS® Visual Analytics), the malicious Javascript is executed in the user's browser.

Click the Hot Fix tab in this note to access the hot fix for this issue.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Visual AnalyticsCloud Foundry8.5Viya
Linux for x648.5Viya
Microsoft® Windows® for x648.5Viya
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.