![]() | ![]() | ![]() | ![]() | ![]() |
Severity: Medium
Description: The HTML Commons component in SAS 9.4 Web Infrastructure Platform includes a version of JQuery that is affected by the vulnerability described in CVE-2020-11022.
Potential Impact: A user's web browser might execute untrustworthy code.
Click the Hot Fix tab in this note to access the hot fix for this issue.
Note: The Hot Fix for this issue does not upgrade the overall version of JQuery that is used—it remains at 2.2.3. Rather, the hot fix implements the code patch that was incorporated in newer versions of JQuery within the current SAS library. As a result, automated security scanners might still flag the SAS library for this vulnerability even though the patch has been applied.
Product Family | Product | System | Product Release | SAS Release | ||
Reported | Fixed* | Reported | Fixed* | |||
SAS System | SAS Web Infrastructure Platform | Microsoft® Windows® for x64 | 9.4_M6 | 9.4 TS1M6 | ||
64-bit Enabled AIX | 9.4_M6 | 9.4 TS1M6 | ||||
64-bit Enabled Solaris | 9.4_M6 | 9.4 TS1M6 | ||||
HP-UX IPF | 9.4_M6 | 9.4 TS1M6 | ||||
Linux for x64 | 9.4_M6 | 9.4 TS1M6 | ||||
Solaris for x64 | 9.4_M6 | 9.4 TS1M6 |