SUPPORT / SAMPLES & SAS NOTES
 

Support

Problem Note 67000: The HTML Commons component in SAS® 9.4 Web Infrastructure Platform is affected by the JQuery vulnerability that is described in CVE-2020-11022

DetailsHotfixAboutRate It

Severity: Medium

Description: The HTML Commons component in SAS 9.4 Web Infrastructure Platform includes a version of JQuery that is affected by the vulnerability described in CVE-2020-11022.

Potential Impact: A user's web browser might execute untrustworthy code.

Click the Hot Fix tab in this note to access the hot fix for this issue. 

Note: The Hot Fix for this issue does not upgrade the overall version of JQuery that is used—it remains at 2.2.3. Rather, the hot fix implements the code patch that was incorporated in newer versions of JQuery within the current SAS library. As a result, automated security scanners might still flag the SAS library for this vulnerability even though the patch has been applied.



Operating System and Release Information

Product FamilyProductSystemProduct ReleaseSAS Release
ReportedFixed*ReportedFixed*
SAS SystemSAS Web Infrastructure PlatformMicrosoft® Windows® for x649.4_M69.4 TS1M6
64-bit Enabled AIX9.4_M69.4 TS1M6
64-bit Enabled Solaris9.4_M69.4 TS1M6
HP-UX IPF9.4_M69.4 TS1M6
Linux for x649.4_M69.4 TS1M6
Solaris for x649.4_M69.4 TS1M6
* For software releases that are not yet generally available, the Fixed Release is the software release in which the problem is planned to be fixed.