SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 66004: SAS® Studio contains a broken access-control vulnerability in its file download capability

DetailsHotfixAboutRate It

Severity: Medium

Description: A broken access-control vulnerability in SAS Studio allows a file download when the capability has been revoked.

Potential Impact: A user could perform file downloads when the capability has been revoked.

Click the Hot Fix tab in this note for a link to instructions about accessing and applying the software update.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS StudioMicrosoft® Windows® for x645.2Viya
SAS SystemSAS Studio for ViyaLinux for x645.22020.1ViyaViya platform
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.